API Resources

POST
/v3/purls

Request vulnerabilities related to a list of PURLs, up to 100 per request

Based on the specified PURLs, this endpoint will return a list PURLs with related vulnerabilities.

You can find a list of supported package managers here

Each request accepts up to 100 PURLs. Requests with more are rejected with a 400 — see Errors. To look up more than 100 PURLs, split them into batches of up to 100 and send one request per batch.

Request Body

purls
list required
Package URL Schemes. Up to 100 per request.

Example Requests

curl --request POST \
  --url https://api.vulncheck.com/v3/purls \
  --header 'Authorization: Bearer insert_token_here' \
  --data '[
  "pkg:hex/coherence@0.1.2",
  "pkg:conan/assimp@5.1.0",
  "pkg:conan/crossguid@0.2.2",
]'

Response

{
  "_benchmark": 0.173334,
  "_meta": {
    "timestamp": "2025-12-12T21:22:37.41976683Z",
    "total_documents": 1
  },
  "data": [
    {
      "purl": "pkg:hex/coherence@0.1.2",
      "purl_struct": {
        "type": "hex",
        "namespace": "",
        "name": "coherence",
        "version": "0.1.2",
        "qualifiers": null,
        "subpath": ""
      },
      "cves": [
        "CVE-2018-20301"
      ],
      "vulnerabilities": [
        {
          "detection": "CVE-2018-20301",
          "fixed_version": "0.5.2"
        }
      ]
    }
  ]
}

Errors

A request with more than 100 PURLs returns a 400. For example, a request with 101 PURLs returns:

{
  "error": true,
  "errors": [
    "101 > max size 100: too many purls"
  ]
}