[CTI] Rate Limits, Query Params, Batch Requests, and Request Intervals

30 views
Skip to first unread message

Alex Nevsen

unread,
Oct 14, 2025, 3:54:37 PM (5 days ago) Oct 14
to Wazuh | Mailing List
Greetings Wazuh team,

I'm using the Wazuh CTI to retrieve CVE information, including fixed package versions for vulnerability enrichment.

Could you please clarify:

1. Are there any rate limits for requests?
2. What is the recommended request interval to avoid throttling?
3. Are query parameters supported to filter specific data? (e.g., `affected[source]=Canonical`, `affected[product]=openssl`)?
4. What is the maximum number of requests per minute/hour/day etc?
5. Is there a way to retrieve multiple CVEs in a single request (batch/bulk endpoint)?
6. If batch requests are supported, what is the maximum batch size?

I'm planning to use this CTI for periodic vulnerability updates in OpenSearch,
so I want to ensure compliance with usage limits and optimize performance.

Thank you!

Leonardo López

unread,
Oct 16, 2025, 7:59:02 PM (3 days ago) Oct 16
to Wazuh | Mailing List
Hello Alex,
We are consulting the CTI team to provide you the information.
Sorry the delay
Thanks!
Reply all
Reply to author
Forward
0 new messages