Vulnerability-Lookup 4.0.0 is out – Federation is here (www.vulnerability-lookup.org)
from cm0002@toast.ooo to cybersecurity@infosec.pub on 16 Feb 2026 18:01
https://toast.ooo/post/12299938

Today we’re releasing Vulnerability-Lookup 4.0.0, and this is a big one.

πŸ”„ Remote Instance Synchronization

This version is paving the way for federated deployments of Vulnerability-Lookup instances. You can now synchronize multiple Vulnerability-Lookup instances and share:

  • πŸ’¬ Comments
  • πŸ“¦ Bundles
  • πŸ‘οΈ Sightings
  • 🚨 KEV entries (GCVE BCP-07)

This introduces a true federated model for vulnerability intelligence sharing.

<img alt="" src="https://infosec.pub/api/v3/image_proxy?url=https%3A%2F%2Flemmy.ml%2Fpictrs%2Fimage%2F4e46542e-819a-418f-889e-b2dc26ce9372.png">

<img alt="" src="https://infosec.pub/api/v3/image_proxy?url=https%3A%2F%2Flemmy.ml%2Fpictrs%2Fimage%2Fd5d1ab8a-00a6-4cfb-908d-2cbbda0e0b86.png">

<img alt="" src="https://infosec.pub/api/v3/image_proxy?url=https%3A%2F%2Flemmy.ml%2Fpictrs%2Fimage%2F406ea2c3-f5ea-4d77-a9b2-958128c37c08.png">

Full breakdown available here:

πŸ‘‰ vulnerability-lookup.org/…/vulnerability-lookup-4…

Let’s take a look at all the notable changes.

πŸ” Remote Instance Synchronization – What’s Inside

This release introduces a complete sync engine designed for reliability, transparency, and operational control.

A local instance can now pull objects β€” including bundles, comments, sightings, and KEV entries β€” from configured remote Vulnerability-Lookup instances via their public APIs.

The synchronization engine includes:

  • Remote instance management with per-object-type synchronization controls
  • Timestamp-based update detection to keep data consistent
  • Asynchronous scheduler with graceful shutdown support
  • CLI command and systemd service template for automation
  • Administrative controls to trigger synchronization manually
  • Visual indicators in the interface to clearly identify synchronized objects

πŸ”Œ Feeder Improvements

Expanded data ingestion:

  • New RustSec OSV feeder
  • New OSS-Fuzz feeder (with YAML support in OSV)
  • More generic CSAF and OSV templates

This strengthens Vulnerability-Lookup’s position as a correlation hub across heterogeneous vulnerability sources.

<img alt="" src="https://infosec.pub/api/v3/image_proxy?url=https%3A%2F%2Flemmy.ml%2Fpictrs%2Fimage%2F294f4de3-73b7-4408-af69-f0ee04084219.png">

🎨 UI Improvements

  • Redesigned global dashboard layout for better visibility and structure.

More details:

πŸ‘‰ vulnerability-lookup.org/…/vulnerability-lookup-4…

If you’re running Vulnerability-Lookup and interested in interconnecting instances across organizations or teams β€” this release is for you.

πŸ”— Project: https://www.vulnerability-lookup.org/ πŸ“¦ Code: https://github.com/vulnerability-lookup/vulnerability-lookup

Feedback, experiments, and federated setups welcome.

Feel free to create an account on the instance operated by CIRCL (Computer Incident Response Center Luxembourg):

vulnerability.circl.lu

πŸ’ΆπŸ‡ͺπŸ‡Ί Funding

Vulnerability-Lookup is co-funded by CIRCL (Computer Incident Response Center Luxembourg) and by the European Union via the hashtag hashtag#NGSOTI project. More information on the page from Restena Foundation: www.restena.lu/en/project/ngsoti

#VulnerabilityManagement #CVE #KEV #GCVE #CVD #CyberSecurity #Federation

#cybersecurity

threaded - newest