{"bulk_dumps":{"available":true,"note":"Optional, instance-specific open-data convenience \u2014 not a sync mechanism. Re-pulling a full export on a schedule is worse for the server than an API client using since= and yields stale data between runs.","url":"https://vulnerability.circl.lu/dumps/"},"contact":{"email":"mailto:csirt@opendfir.org","url":"https://cve.radiocsirt.org/about"},"documentation":{"access_patterns":"https://www.vulnerability-lookup.org/documentation/access-patterns.html","api":"https://cve.radiocsirt.org/api","general":"https://www.vulnerability-lookup.org/documentation"},"expires":"2027-10-02T07:59:47+00:00","instance":{"base_url":"https://cve.radiocsirt.org","name":"Vulnerability-Lookup","operator":"RadioCSIRT","operator_url":"https://cve.radiocsirt.org","uuid":"06371011-5260-4c1d-af16-8364186e3396"},"policy_url":"https://cve.radiocsirt.org/.well-known/api-policy.json","rate_limits":{"enforced":true,"key":"X-API-KEY when present (per-key bucket); IP address otherwise.","limits":{"anonymous":"60 per minute","authenticated":"1/second"},"policy":"Read endpoints under /api are rate limited per client: anonymous callers by IP address, authenticated callers by API key. The enforced values are in the rate_limits block of this document; responses carry standard X-RateLimit-* headers, and 429 responses carry Retry-After.","runtime_headers":"X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset are emitted on rate-limited responses; 429 responses carry Retry-After."},"sync":{"canonical_path":"api+stream","guidance":"Use the API for synchronisation. The 'since=' parameter on /api/vulnerability/ (and equivalent endpoints) supports incremental pulls. The pub/sub stream provides real-time updates without polling. Do not enumerate the API to mirror the dataset.","incremental_endpoint":"/api/vulnerability/?since=YYYY-MM-DD","stream_auth":"X-API-KEY header (per-user API token) carrying the stream:subscribe permission","stream_available":true,"stream_endpoint":"/pubsub/subscribe/{topic}","stream_format":"text/event-stream (Server-Sent Events)","stream_topics":["vulnerability","comment","bundle","sighting"]},"user_agent":{"expectation":"Identify automated clients with a meaningful User-Agent string that includes a contact URL or email."},"version":"1"}
