Support with `hasCertAlerts` and `hasCertNotes ` with the NVD API

I was reading your very informative post about the NVD API, specifically about CVEs:

In the post you refer to these filters

  • hasCertAlerts: if set, only returns the CVE that contain a Technical Alert from US-CERT
  • hasCertNotes: if set, only returns the CVE that contain a Vulnerability Note from CERT/CC

However, I can’t seem to get these to return any data.

Here is an example of my request for hasCertNotes:

curl --location '' \
--header 'apiKey: HIDDEN'

But the response is empty.

Can someone give me any pointers?

Hey @0101001001001 ,

You’re soooooo close :slight_smile:

The hasCertNotes and hasCertAlerts properties are not boolean. You just need to pass them with a null value to get a response.


curl --location '' \
--header 'apiKey: REDACTED'
    "resultsPerPage": 5,
    "startIndex": 0,
    "totalResults": 5,
    "format": "NVD_CVE",
    "version": "2.0",
    "timestamp": "2024-06-05T11:18:32.650",
    "vulnerabilities": [
            "cve": {
                "id": "CVE-1999-0067",
                "sourceIdentifier": "",
                "published": "1996-03-20T05:00:00.000",
                "lastModified": "2024-01-26T20:00:52.747",
                "vulnStatus": "Analyzed",
                "descriptions": [
                        "lang": "en",
                        "value": "phf CGI program allows remote command execution through shell metacharacters."
                "metrics": {
                    "cvssMetricV2": [
                            "source": "",
                            "type": "Primary",
                            "cvssData": {
                                "version": "2.0",
                                "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                                "accessVector": "NETWORK",
                                "accessComplexity": "LOW",
                                "authentication": "NONE",
                                "confidentialityImpact": "COMPLETE",
                                "integrityImpact": "COMPLETE",
                                "availabilityImpact": "COMPLETE",
                                "baseScore": 10.0
                            "baseSeverity": "HIGH",
                            "exploitabilityScore": 10.0,
                            "impactScore": 10.0,
                            "acInsufInfo": false,
                            "obtainAllPrivilege": true,
                            "obtainUserPrivilege": false,
                            "obtainOtherPrivilege": false,
                            "userInteractionRequired": false
                "weaknesses": [
                        "source": "",
                        "type": "Primary",
                        "description": [
                                "lang": "en",
                                "value": "CWE-78"
                "configurations": [
                        "nodes": [
                                "operator": "OR",
                                "negate": false,
                                "cpeMatch": [
                                        "vulnerable": true,
                                        "criteria": "cpe:2.3:a:apache:http_server:1.0.3:*:*:*:*:*:*:*",
                                        "matchCriteriaId": "B5EA86B9-4F86-4ADA-BC6A-4F6E261848F6"
                                        "vulnerable": true,
                                        "criteria": "cpe:2.3:a:ncsa:ncsa_httpd:1.5a:*:export:*:*:*:*:*",
                                        "matchCriteriaId": "7D7735EC-8C34-4C2B-B8CC-154182D070C2"
                "references": [
                        "url": "",
                        "source": "",
                        "tags": [
                            "Third Party Advisory",
                            "US Government Resource"
                        "url": "",
                        "source": "",
                        "tags": [
                            "Broken Link"
                        "url": "",
                        "source": "",
                        "tags": [
                            "Broken Link",
                            "Third Party Advisory",
                            "VDB Entry"

You know they’re related to CertAlerts or CertAlerts (if not using these filters) b/c the references.tags property of the CVE will contain US Government Resource


"tags": [
                            "Broken Link",
                            "Third Party Advisory",
                            "US Government Resource"
1 Like