Cybersecurity and Infrastructure Security Agency Schema API

JSON Schema for the KEV catalog

Operations 1

GET /sites/default/files/feeds/known_exploited_vulnerabilities_schema.json Get the JSON Schema for the KEV catalog #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cybersecurity-and-infrastructure-security-agency-schema-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cybersecurity-and-infrastructure-security-agency-schema-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: CISA Known Exploited Vulnerabilities () Catalog KEV Schema API
  description: The CISA Known Exploited Vulnerabilities (KEV) Catalog is the authoritative source of vulnerabilities that have been actively exploited in the wild. CISA publishes the catalog as a machine-readable JSON feed (and CSV) updated within minutes of catalog changes during U.S. business hours. Federal civilian agencies are required by Binding Operational Directive 22-01 to remediate KEV-listed vulnerabilities by the dueDate provided in each entry. This OpenAPI describes the unauthenticated public JSON feed and its mirror on GitHub.
  version: '1.0'
  contact:
    name: CISA
    url: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
servers:
- url: https://www.cisa.gov
  description: Canonical CISA-hosted feed
- url: https://raw.githubusercontent.com/cisagov/kev-data/develop
  description: GitHub mirror maintained by cisagov/kev-data
tags:
- name: Schema
  description: JSON Schema for the KEV catalog
paths:
  /sites/default/files/feeds/known_exploited_vulnerabilities_schema.json:
    get:
      tags:
      - Schema
      summary: Get the JSON Schema for the KEV catalog
      description: Returns the JSON Schema document used to validate the KEV JSON feed.
      operationId: getKevJsonSchema
      responses:
        '200':
          description: KEV JSON Schema
          content:
            application/json:
              schema:
                type: object