cve-bin-tool

Install command:
brew install cve-bin-tool

Scans binaries and SBOMs for known vulnerabilities and prepares reports

https://github.com/ossf/cve-bin-tool

License: GPL-3.0-or-later

Development: Pull requests

Formula JSON API: /api/formula/cve-bin-tool.json

Formula code: cve-bin-tool.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
tahoe
sequoia
sonoma
macOS on
Intel
sonoma
Linux ARM64
x86_64

Current versions:

stable 3.4
head ⚡️ HEAD

Revision: 2

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
cryptography 50.0.1 Cryptographic recipes and primitives for Python
libyaml 0.2.5 YAML Parser
pillow 12.3.0 Friendly PIL fork (Python Imaging Library)
python@3.14 3.14.7 Interpreted, interactive, object-oriented programming language
rpds-py 2026.6.3 Python bindings to Rust's persistent data structures

Depends on when building from source:

cmake 4.4.3 Cross-platform make
rust 1.98.0 Safe, concurrent, practical language

Binaries: csv2cve, cve-bin-tool, mismatch

Known vulnerabilities in the current version:

GHSA-j5g9-f88f-gfj3 (high) httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

Data from Homebrew/advisory-database. Run brew vulns cve-bin-tool for a live check.

Analytics:

30 days90 days365 days
Installs50149149
Installs on Request50149149
Build Errors0