iridium-soda / VulnCodeCollector

A lightweight tool designed to automatically crawl CVE-related source code, with the capability to export content in a readable database format(i.e. 多维表格) for applications like Lark or Tencent Docs.
Apache License 2.0
0 stars 0 forks source link

Unable to fetch data from OPENCVE in some situations #4

Closed iridium-soda closed 1 month ago

iridium-soda commented 1 month ago

似乎没有稳定复现

iridium-soda commented 1 month ago

检查得到NVD的请求在开始运行之后一段时间得到403,猜测可能是qps过高造成接口过载

iridium-soda commented 1 month ago

https://nvd.nist.gov/developers/start-here

Rate Limits NIST firewall rules put in place to prevent denial of service attacks can thwart your application if it exceeds a predetermined rate limit. The public rate limit (without an API key) is 5 requests in a rolling 30 second window; the rate limit with an API key is 50 requests in a rolling 30 second window. Requesting an API key significantly raises the number of requests that can be made in a given time frame. However, it is still recommended that your application sleeps for several seconds between requests so that legitimate requests are not denied, and all requests are responded to in sequence.