v0.2.0
NVIDIA/cosmosv0.2.0Jun 22, 2026by mukul975
AI Summary
This release introduces a major new `triage_cve` orchestrator for concurrent vulnerability analysis using NVD, EPSS, and CISA KEV data sources. It also includes significant security hardening measures, such as SSRF defense and the removal of sampling handlers, alongside infrastructure improvements for concurrency and Docker.
Key Highlights
- New `triage_cve` orchestrator for concurrent NVD, EPSS, and CISA KEV analysis with composite risk scoring.
- Security hardening including SSRF defense, removal of sampling handlers, and centralized secret management.
- CISA KEV hard override ensures listed CVEs are always marked CRITICAL.
- Integration of new data sources: VulnCheck NVD++, CIRCL hashlookup, and HIBP Pwned Passwords.
- MCP enhancements featuring new resources, prompts, and streamable-HTTP transport support.
New Features
- Added `triage_cve` orchestrator with `depth` parameter (quick/standard/deep) and SSVC v2 decision support.
- Implemented VulnCheck NVD++ fallback for NVD unreachability.
- Added CIRCL hashlookup for known-good allowlists.
- Integrated HIBP Pwned Passwords range API (keyless k-anonymity).
- Added new MCP resources: `kev://catalog`, `epss://scores/{cve_id}`, `manifest://tool-hash`.
- Added new MCP prompts: `patch_decision`, `compare_and_prioritize`, `dependency_triage`.
- Enabled Streamable-HTTP transport via `MCP_TRANSPORT=http`.
- Implemented SSRF defense with scheme allowlist and private IP rejection.
- Server no longer registers sampling handler to prevent MCP-sampling attacks.
Full Release Notes
## CVE MCP Server v0.2.0
A major feature release. **Additive** — all existing tools remain registered; the new `triage_cve` orchestrator is the recommended entry point.
### ⭐ Orchestration
- **`triage_cve`** — one tool call fans out NVD + EPSS + CISA KEV (+ public PoC discovery) concurrently, computes the composite risk score, and returns a clean report. `depth` = `quick` / `standard` / `deep`; **`deep`** also emits an SSVC v2 gated decision (CISA Deployer model → `Act` / `Attend` / `Track*` / `Track`).
- Transparent **VulnCheck NVD++ fallback** used automatically when NIST NVD is unreachable or throttled.
### 🎯 Scoring
- **CISA KEV hard override** — a KEV-listed CVE is always **CRITICAL** (score clamped ≥ 76), regardless of CVSS/EPSS.
- **`scoring_version`** stamped into `triage_cve`, `calculate_risk_score`, and `health_check`.
- CVSS reframed as a **severity** signal (not exploitation-likelihood), per Allodi & Massacci 2014.
### 🔌 New data sources
- **VulnCheck NVD++** (NVD-schema fallback), **CIRCL hashlookup** (known-good allowlist), **HIBP Pwned Passwords** range API (keyless k-anonymity).
### 🧩 MCP enhancements
- **Resources**: `kev://catalog`, `epss://scores/{cve_id}`, `manifest://tool-hash` (SHA-256 over the registered tool surface).
- **Prompts**: `patch_decision`, `compare_and_prioritize`, `dependency_triage`.
- **Streamable-HTTP transport** via `MCP_TRANSPORT=http` (stdio remains the default).
- Expanded `health_check` (scoring version, manifest hash, configured-key status).
### 🔐 Security hardening
- Server **never** registers a sampling handler / never issues `sampling/createMessage` (Unit 42 MCP-sampling attack vector).
- **SSRF** defense: scheme allowlist + resolve-then-validate (rejects private/reserved IPs).
- Secrets centralized as Pydantic `SecretStr`.
### 🏗️ Infrastructure
- Multi-stage non-root **Dockerfile** + `.dockerignore`.
- SQLite **WAL** pragmas for concurrent reads; null-object rate limiter; fixed-interval deterministic retry; async fan-out helper; static Admiralty source-trust table.
**Verified:** ruff clean, 30/30 tests passing.
**Full Changelog:** https://github.com/mukul975/cve-mcp-server/compare/v0.1.0...v0.2.0
## What's Changed
* fix(7): set correct default values for cache and audit by @fergoid in https://github.com/mukul975/cve-mcp-server/pull/8
## New Contributors
* @fergoid made their first contribution in https://github.com/mukul975/cve-mcp-server/pull/8
**Full Changelog**: https://github.com/mukul975/cve-mcp-server/compare/v0.1.0...v0.2.0