cve-bin-tool

Install command:
brew install cve-bin-tool

Scans binaries and SBOMs for known vulnerabilities and prepares reports

https://github.com/ossf/cve-bin-tool

License: GPL-3.0-or-later

Development: Pull requests

Formula JSON API: /api/formula/cve-bin-tool.json

Formula code: cve-bin-tool.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
golden gate ✅
tahoe ✅
sequoia ✅
Linux ARM64 ✅
x86_64 ✅

Current versions:

stable ✅ 3.4
head ⚡️ HEAD

Revision: 3

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
cryptography 50.0.2 Cryptographic recipes and primitives for Python
libyaml 0.2.5 YAML Parser
pillow 12.3.0 Friendly PIL fork (Python Imaging Library)
python@3.14 3.14.8 Interpreted, interactive, object-oriented programming language
rpds-py 2026.9.1 Python bindings to Rust's persistent data structures

Depends on when building from source:

cmake 4.4.4 Cross-platform make
rust 1.99.0 Safe, concurrent, practical language

Binaries: csv2cve, cve-bin-tool, mismatch

Known vulnerabilities in the current version:

GHSA-j5g9-f88f-gfj3 (high) httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

Data from Homebrew/advisory-database. Run brew vulns cve-bin-tool for a live check.

Analytics:

30 days90 days365 days
Installs25121177
Installs (--HEAD)111
Installs on Request25121177
Installs on Request (--HEAD)111
Build Errors0