OpenVAS
The scanner component of Greenbone Community Edition, a vulnerability scan engine that runs a continuously updated feed of vulnerability tests.
- GitHub stars
- 4.8k
- Last commit
- today
- Latest release
- v23.50.26
- Licence
- GPL-2.0
- Self-hosted
- Yes

OpenVAS Scanner is the scanning engine of the Greenbone Community Edition and is also used in Greenbone Enterprise appliances. It performs vulnerability scans by running a set of Vulnerability Tests (VTs) that is updated and extended continuously through a feed.
The module is configured, built and installed with CMake and make, and the INSTALL.md file explains how to set up openvas and expose the scanner to other GVM modules. Release files are signed with the Greenbone Community Feed integrity key. Docker images are published to the Greenbone registry, and a fully containerized setup for the Community Edition is also provided.
The repository also contains a Rust project that aims to replace the existing scanner stack made up of openvas-scanner, ospd-openvas and notus-scanner, simplifying scanning by centralizing everything in one place; for now it uses openvas-scanner as the scan engine. The code is licensed under GPL-2.0. Anyone not comfortable building from source is pointed to the Greenbone Enterprise TRIAL virtual machine.
Key features
- Vulnerability scan engine
- Continuously updated vulnerability test feed
- Signed release files
- Docker images and containerized setup
- Rust-based replacement scanner stack in progress
- Integration with other GVM modules
Pricing: Free and open source under the GPL-2.0 licence.