Overview
Binarly aggregates vulnerability intelligence from multiple sources, eliminating the need for customers to build and maintain their own multi-source pipeline. Sources can be prioritized per product to utilize Finding Variants capabilities. NVD (National Vulnerability Database) is the primary advisory source. Every other source in this list enriches NVD data by adding language- and package-specific advisories, distribution vendor patches, security research, project-level disclosures, and real-world exploitation intelligence. Together they enable findings to carry accurate severity, exploitability context, and patch status across a wide range of targets. For the best results, sources are matched against the ecosystem configured for each product (e.g. Ubuntu, Red Hat, Debian). This allows the platform to cross-reference distribution-specific patches against the relevant advisory sources, ensuring findings reflect the actual patch state of the scanned environment rather than upstream version numbers alone. Source IDs (e.g.nvd, ghsa, brly) appear in API responses and report exports, and can be used to configure Finding Variants per product.
Primary Source
Vulnerability Databases
Broad, cross-ecosystem vulnerability databases that complement NVD with independently curated advisory data.Enrichment Sources
Sources used to enrich and cross-check the canonical CVE data NVD is built on.Language & Package Sources
Language and package-manager-specific advisories provide vulnerability data that NVD alone does not always capture with sufficient detail or timeliness.Distribution Sources
Linux distribution vendors often backport security fixes without changing upstream version numbers. These sources allow Binarly to account for patched packages in version-based detection and reduce false positives.Security Vendor Sources
Project Sources
Direct vulnerability disclosures maintained by widely-deployed open-source projects. These may include additional context or severity assessments that differ from NVD.Exploitation Intelligence Sources
These sources provide signals about whether a vulnerability has been actively exploited in the wild or has known public exploit code. They feed directly into risk scoring and reachability analysis, allowing Binarly to surface the highest-priority findings first.Related
- Finding Variants — Configure alternative data sources per product to override default finding data
- Detection Methods — How Binarly identifies vulnerabilities using version-based and rule-based detection
- Risk Scoring — How exploitation intelligence sources influence finding priority
- Reachability — How reachability analysis uses exploitability signals to reduce noise