generated: '2026-08-19' method: searched source: >- https://developer.cisco.com/docs/psirt/ , https://github.com/CiscoPSIRT/openVulnAPI/blob/master/README.md , https://www.cisco.com/.well-known/csaf/provider-metadata.json , and the Cisco-published OpenAPI 3.0.3. description: >- This is a vulnerability-disclosure API, and its standards conformance is unusually strong on the DATA side and unusually thin on the API-mechanics side. Cisco explicitly implements the security-content standards — CSAF, CVRF, CVE, CWE, CVSS, OVAL — and is a registered CSAF trusted provider. It implements almost none of the modern HTTP/API conventions: no RFC 9457 problem details, no RFC 8594 sunset headers, no RFC 9116 security.txt on the API host itself, no standard pagination envelope beyond pageIndex/pageSize. standards: - id: csaf-2.0 name: OASIS Common Security Advisory Framework 2.0 conforms: true role: csaf_trusted_provider evidence: >- https://www.cisco.com/.well-known/csaf/provider-metadata.json declares "role": "csaf_trusted_provider", publisher "Cisco PSIRT", metadata_version 2.0, list_on_CSAF_aggregators true. Every advisory returned by the API carries a csafUrl field. - id: cvrf-1.1 name: Common Vulnerability Reporting Framework conforms: true status: retiring evidence: >- Advisories carry a cvrf_url field and the /cvrf/* endpoints existed. Cisco: "Cisco will support CVRF until December 31, 2023" and "Cisco recommends focusing on CSAF as CVRF will be phased out". The /cvrf/* operations are now deprecated:true with a 410 Gone response. - id: cve name: Common Vulnerabilities and Exposures conforms: true evidence: >- /cve/{cve_id} is a first-class query endpoint; every advisory carries a cves[] field. Cisco is a CVE Numbering Authority. - id: cwe name: Common Weakness Enumeration conforms: true evidence: Advisories expose a cwe field; listed as a supported standard in the API README. - id: cvss name: Common Vulnerability Scoring System conforms: true evidence: Advisories expose cvss_base_score; listed as a supported standard in the API README. - id: oval name: Open Vulnerability and Assessment Language conforms: true evidence: >- OVAL is one of the machine-consumable formats the openVuln API was built to deliver, alongside CVRF/CSAF; /oval/* resource URIs appear throughout Cisco's published error-code reference. - id: sir name: Cisco Security Impact Rating conforms: true evidence: >- /severity/{severity} accepts critical|high|medium|low; advisories carry a sir field. Cisco's own vendor rating, aligned to CVSS bands. - id: oauth2 name: OAuth 2.0 (RFC 6749) client credentials conforms: true evidence: >- POST https://id.cisco.com/oauth2/default/v1/token with grant_type=client_credentials returns a Bearer token, expires_in 3600. Documented at https://developer.cisco.com/docs/psirt/authentication/ - id: rfc6750 name: OAuth 2.0 Bearer Token Usage conforms: true evidence: 'Authorization: Bearer on every request; spec declares http/bearer with bearerFormat JWT.' - id: jwt name: JSON Web Token (RFC 7519) conforms: true evidence: bearerFormat is JWT; Cisco's published example token is a signed RS256 JWT with iss/aud/exp/scp claims. - id: oidc name: OpenID Connect Discovery conforms: false evidence: >- No openIdConnect securityScheme and no /.well-known/openid-configuration on api.cisco.com, apix.cisco.com or developer.cisco.com (504 / 404). id.cisco.com is Okta-backed but no discovery document is advertised for this API. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 504 on both API hosts and 404 on the docs host. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Errors are returned as a bespoke {errorCode, errorMessage} envelope in JSON or XML — not application/problem+json. See errors/cisco-psirt-error-codes.yml. - id: rfc8594 name: Sunset HTTP Header conforms: false evidence: >- Retirement is signalled in the OpenAPI (deprecated:true + 410 Gone + a "Sunset Endpoints" tag) rather than by Sunset/Deprecation response headers. - id: rfc9116 name: security.txt conforms: true scope: corporate evidence: >- https://www.cisco.com/.well-known/security.txt — 200, PGP clear-signed, with Contact mailto:psirt@cisco.com, Policy, Encryption, CSAF and Expires fields. Not served from the API hosts themselves. - id: openapi-3.0 name: OpenAPI Specification 3.0.3 conforms: true evidence: >- Cisco publishes openVulnAPIOAS_3_0_3.yaml first-party at https://github.com/CiscoPSIRT/openVulnAPI/tree/master/swagger — a genuinely rare thing across the Cisco estate. gaps: - No operationId on any of the 30 operations. - No examples in the 200 responses. - Only three tags, all lifecycle-state rather than resource-oriented. - id: asyncapi name: AsyncAPI conforms: false applicable: false evidence: >- No event, webhook or streaming surface exists. Change notification is a human mailing list (openvuln-announce-join@cisco.com) and a bulk CSAF directory at https://www.cisco.com/.well-known/csaf/ — neither is a machine event contract. - id: json-api name: JSON:API conforms: false evidence: Responses are a plain {advisories:[...]} envelope, not JSON:API. - id: odata name: OData conforms: false - id: scim name: SCIM 2.0 conforms: false applicable: false - id: fhir-r4 name: FHIR R4 conforms: false applicable: false - id: fapi name: FAPI conforms: false applicable: false - id: psd2 name: PSD2 conforms: false applicable: false compliance_program: published: true url: https://trustportal.cisco.com/c/r/ctp/home.html frameworks: [SOC 2, ISO 27001, FedRAMP, BSI C5, GDPR] scope_caveat: >- Corporate and per-product attestations obtained through the Cisco Trust Portal. The PSIRT openVuln API is not itself listed as a Trust Package — see security/cisco-psirt-trust-center.yml. summary: conforms_count: 11 fails_count: 6 not_applicable_count: 5