from cedric@lemmy.ml to security@lemmy.ml on 10 Jul 10:52
https://lemmy.ml/post/49858491
Vulnerability-Lookup now ingests Red Hatβs per-CVE CSAF VEX documents and attaches them straight to the vulnerabilities youβre already tracking. Which products are affected? Which are fixed? Which were never affected at all? One glance at the new VEX tab β or the EPSS-style VEX badge right in the vulnerability header β and you know.
No more digging through vendor advisories to answer βdoes this CVE actually matter to us?β π


Also in this release:
β New /api/vex endpoints β VEX data, fully machine-readable π Per-user enable/disable of CNA publication, with a dedicated admin overview π¬ Admin overview for KEV catalog e-mail subscriptions + richer digest e-mails (entry titles, affected vendors & products) π οΈ A batch of feeder robustness fixes β no more full re-imports or notification storms after a partial download failure

Vulnerability-Lookup is open source, and you can run your own instance today (www.vulnerability-lookup.org/β¦/installation.html).
π Release post: vulnerability-lookup.org/β¦/vulnerability-lookup-5β¦
β GitHub: github.com/β¦/vulnerability-lookup
Feel free to create an account on the instance operated by CIRCL: π vulnerability.circl.lu/user/signup
π References
Source code: github.com/β¦/vulnerability-lookup
Examples:
- vulnerability.circl.lu/vuln/CVE-2026-1207#vex
- vulnerability.circl.lu/vuln/CVE-2026-53359#vex
- vulnerability.circl.lu/vuln/CVE-2026-4631#vex
- vulnerability.circl.lu/vuln/CVE-2023-39361#vex
πΆπͺπΊ Funding
Vulnerability-Lookup is co-funded by CIRCL and by the European Union through the #NGSOTI project.
More information from the Restena Foundation: www.restena.lu/en/project/ngsoti
#VulnerabilityManagement #VEX #CSAF #CVE #OpenSource #CyberSecurity #ThreatIntelligence
threaded - newest