You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CVSS v4.0变更后NVD API密钥突然失效问题求助

NVD API 周期性出现「Invalid API key」错误排查求助

我有一套使用NVD API拉取漏洞数据的流程,已稳定运行多年。近期日志中突然周期性出现「Error: Invalid API key」错误,示例日志如下:

Downloaded 6000 CVEs.
Process finished at 2024-07-02 11:02:55
Total duration: 173.34 seconds
Downloaded 8000 CVEs.
Error: Invalid API key
Process finished at 2024-07-02 15:01:10
Total duration: 0.30 seconds
Downloaded 0 CVEs.
Process finished at 2024-07-02 17:00:37
Total duration: 1.92 seconds
Downloaded 0 CVEs.
Error: Invalid API key

我使用以下Python测试代码验证API密钥有效性:

import requests
import logging
import time

# Configure logging
logging.basicConfig(filename='/<dir>/api_key_check.log', level=logging.INFO, format='%(asctime)s:%(levelname)s:%(message)s')

def is_valid_api_key(apiKey, retries=3, delay=5, timeout=10):
    test_url = 'https://services.nvd.nist.gov/rest/json/cves/2.0'
    test_params = {'startIndex': 0, 'resultsPerPage': 1}
    headers = {'apiKey': apiKey}

    for attempt in range(retries):
        try:
            logging.info(f"Attempt {attempt + 1} to check API key.")
            test_response = requests.get(test_url, params=test_params, headers=headers, timeout=timeout)
            if test_response.status_code == 200:
                logging.info("API key is valid.")
                return True
            elif test_response.status_code == 403:
                logging.error("Forbidden: The API key might be invalid or rate-limited.")
                return False
            else:
                logging.error(f"Unexpected status code {test_response.status_code} on attempt {attempt + 1}")
        except requests.Timeout:
            logging.error(f"Request timed out on attempt {attempt + 1}")
        except requests.RequestException as e:
            logging.error(f"Request failed on attempt {attempt + 1}: {e}")
        time.sleep(delay)

    logging.error("API key validation failed after multiple attempts.")
    return False

# Replace 'your_api_key_here' with your actual API key
apiKey = 'your_api_key_here'
if is_valid_api_key(apiKey):
    print("API key is valid.")
else:
    print("Error: Invalid API key.")

运行测试代码后返回「Error: Invalid API key.」。该问题已持续4天,NIST及NVD官方响应迟缓,求助是否有用户遇到同类问题或解决建议。官方讨论组为NVD官方邮件列表。

内容的提问来源于stack exchange,提问作者Scouse_Bob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 15:31:04