{
  "x402Version": 2,
  "id": 4488,
  "slug": "4488",
  "resource": "https://dependency-risk.use.x402atlas.com/sbom",
  "description": "CycloneDX SBOM vulnerability check — analyze bounded JSON 1.5 software bill of materials components against OSV and prioritize exact CVE matches from CISA KEV without remote document fetches.",
  "type": "http",
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "amount": "20000",
      "maxTimeoutSeconds": 300
    },
    {
      "scheme": "exact",
      "network": "eip155:137",
      "payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
      "asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
      "amount": "20000",
      "maxTimeoutSeconds": 300
    },
    {
      "scheme": "exact",
      "network": "eip155:42161",
      "payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
      "asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
      "amount": "20000",
      "maxTimeoutSeconds": 300
    }
  ],
  "outputSchema": {
    "bazaar": {
      "category": "security",
      "info": {
        "input": {
          "body": {
            "document": {
              "bomFormat": "CycloneDX",
              "components": [
                {
                  "name": "log4j-core",
                  "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1",
                  "type": "library",
                  "version": "2.14.1"
                }
              ],
              "specVersion": "1.5"
            }
          },
          "bodyType": "json",
          "method": "POST",
          "type": "http"
        },
        "output": {
          "example": {
            "operation": "sbom-check",
            "partial": false,
            "results": [
              {
                "findings": [
                  {
                    "affected": [
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.0-alpha1"
                              },
                              {
                                "fixed": "2.25.4"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.0",
                          "2.0-alpha1",
                          "2.0-alpha2",
                          "2.0-beta1",
                          "2.0-beta2",
                          "2.0-beta3",
                          "2.0-beta4",
                          "2.0-beta5",
                          "2.0-beta6",
                          "2.0-beta7",
                          "2.0-beta8",
                          "2.0-beta9",
                          "2.0-rc1",
                          "2.0-rc2",
                          "2.0.1",
                          "2.0.2",
                          "2.1",
                          "2.10.0",
                          "2.11.0",
                          "2.11.1",
                          "2.11.2",
                          "2.12.0",
                          "2.12.1",
                          "2.12.2",
                          "2.12.3",
                          "2.12.4",
                          "2.13.0",
                          "2.13.1",
                          "2.13.2",
                          "2.13.3",
                          "2.14.0",
                          "2.14.1",
                          "2.15.0",
                          "2.16.0",
                          "2.17.0",
                          "2.17.1",
                          "2.17.2",
                          "2.18.0",
                          "2.19.0",
                          "2.2",
                          "2.20.0",
                          "2.21.0",
                          "2.21.1",
                          "2.22.0",
                          "2.22.1",
                          "2.23.0",
                          "2.23.1",
                          "2.24.0",
                          "2.24.1",
                          "2.24.2",
                          "2.24.3",
                          "2.25.0",
                          "2.25.1",
                          "2.25.2",
                          "2.25.3",
                          "2.3",
                          "2.3.1",
                          "2.3.2",
                          "2.4",
                          "2.4.1",
                          "2.5",
                          "2.6",
                          "2.6.1",
                          "2.6.2",
                          "2.7",
                          "2.8",
                          "2.8.1",
                          "2.8.2",
                          "2.9.0",
                          "2.9.1"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "3.0.0-alpha1"
                              },
                              {
                                "last_affected": "3.0.0-beta3"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "3.0.0-alpha1",
                          "3.0.0-beta1",
                          "3.0.0-beta2",
                          "3.0.0-beta3"
                        ]
                      }
                    ],
                    "aliases": [
                      "CVE-2026-34480"
                    ],
                    "fixed_versions": [
                      "2.25.4"
                    ],
                    "id": "GHSA-3pxv-7cmr-fjr4",
                    "max_severity": "medium",
                    "modified": "2026-04-16T11:29:10.536806482Z",
                    "published": "2026-04-10T18:31:17Z",
                    "references": [
                      {
                        "type": "ADVISORY",
                        "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34480"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/apache/logging-log4j2/pull/4077"
                      },
                      {
                        "type": "PACKAGE",
                        "url": "https://github.com/apache/logging-log4j2"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/cyclonedx/vdr.xml"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/security.html#CVE-2026-34480"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2026/04/10/9"
                      }
                    ],
                    "severity": [
                      {
                        "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N",
                        "type": "CVSS_V4"
                      }
                    ],
                    "summary": "Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters",
                    "withdrawn": false
                  },
                  {
                    "affected": [
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.12.0"
                              },
                              {
                                "fixed": "2.25.4"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.12.0",
                          "2.12.1",
                          "2.12.2",
                          "2.12.3",
                          "2.12.4",
                          "2.13.0",
                          "2.13.1",
                          "2.13.2",
                          "2.13.3",
                          "2.14.0",
                          "2.14.1",
                          "2.15.0",
                          "2.16.0",
                          "2.17.0",
                          "2.17.1",
                          "2.17.2",
                          "2.18.0",
                          "2.19.0",
                          "2.20.0",
                          "2.21.0",
                          "2.21.1",
                          "2.22.0",
                          "2.22.1",
                          "2.23.0",
                          "2.23.1",
                          "2.24.0",
                          "2.24.1",
                          "2.24.2",
                          "2.24.3",
                          "2.25.0",
                          "2.25.1",
                          "2.25.2",
                          "2.25.3"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "3.0.0-alpha1"
                              },
                              {
                                "last_affected": "3.0.0-beta3"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "3.0.0-alpha1",
                          "3.0.0-beta1",
                          "3.0.0-beta2",
                          "3.0.0-beta3"
                        ]
                      }
                    ],
                    "aliases": [
                      "CVE-2026-34477"
                    ],
                    "fixed_versions": [
                      "2.25.4"
                    ],
                    "id": "GHSA-6hg6-v5c8-fphq",
                    "max_severity": "medium",
                    "modified": "2026-04-17T12:29:10.521430176Z",
                    "published": "2026-04-10T18:31:17Z",
                    "references": [
                      {
                        "type": "ADVISORY",
                        "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34477"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/apache/logging-log4j2/pull/4075"
                      },
                      {
                        "type": "PACKAGE",
                        "url": "https://github.com/apache/logging-log4j2"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/cyclonedx/vdr.xml"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/security.html#CVE-2026-34477"
                      }
                    ],
                    "severity": [
                      {
                        "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N",
                        "type": "CVSS_V4"
                      }
                    ],
                    "summary": "Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration",
                    "withdrawn": false
                  },
                  {
                    "affected": [
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.13.0"
                              },
                              {
                                "fixed": "2.16.0"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.13.0",
                          "2.13.1",
                          "2.13.2",
                          "2.13.3",
                          "2.14.0",
                          "2.14.1",
                          "2.15.0"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "0"
                              },
                              {
                                "fixed": "2.12.2"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.0",
                          "2.0-alpha1",
                          "2.0-alpha2",
                          "2.0-beta1",
                          "2.0-beta2",
                          "2.0-beta3",
                          "2.0-beta4",
                          "2.0-beta5",
                          "2.0-beta6",
                          "2.0-beta7",
                          "2.0-beta8",
                          "2.0-beta9",
                          "2.0-rc1",
                          "2.0-rc2",
                          "2.0.1",
                          "2.0.2",
                          "2.1",
                          "2.10.0",
                          "2.11.0",
                          "2.11.1",
                          "2.11.2",
                          "2.12.0",
                          "2.12.1",
                          "2.2",
                          "2.3",
                          "2.3.1",
                          "2.3.2",
                          "2.4",
                          "2.4.1",
                          "2.5",
                          "2.6",
                          "2.6.1",
                          "2.6.2",
                          "2.7",
                          "2.8",
                          "2.8.1",
                          "2.8.2",
                          "2.9.0",
                          "2.9.1"
                        ]
                      }
                    ],
                    "aliases": [
                      "CVE-2021-45046"
                    ],
                    "fixed_versions": [
                      "2.16.0",
                      "2.12.2"
                    ],
                    "id": "GHSA-7rjr-3q55-vv33",
                    "kev": {
                      "cve_id": "CVE-2021-45046",
                      "cwes": [
                        "CWE-917"
                      ],
                      "date_added": "2023-05-01",
                      "due_date": "2023-05-22",
                      "known_ransomware_campaign_use": "Known",
                      "notes": "https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046",
                      "product": "Log4j2",
                      "required_action": "Apply updates per vendor instructions.",
                      "short_description": "Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.",
                      "vendor_project": "Apache",
                      "vulnerability_name": "Apache Log4j2 Deserialization of Untrusted Data Vulnerability"
                    },
                    "max_severity": "critical",
                    "modified": "2025-10-22T19:37:53.742023Z",
                    "published": "2021-12-14T18:01:28Z",
                    "references": [
                      {
                        "type": "ADVISORY",
                        "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45046"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.openwall.com/lists/oss-security/2021/12/14/4"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.kb.cert.org/vuls/id/930724"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.debian.org/security/2021/dsa-5022"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.cve.org/CVERecord?id=CVE-2021-44228"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046"
                      },
                      {
                        "type": "WEB",
                        "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                      },
                      {
                        "type": "WEB",
                        "url": "https://security.gentoo.org/glsa/202310-16"
                      },
                      {
                        "type": "WEB",
                        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                      },
                      {
                        "type": "WEB",
                        "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/security.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY"
                      },
                      {
                        "type": "ADVISORY",
                        "url": "https://github.com/advisories/GHSA-jfh8-c2jp-5v3q"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/14/4"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/15/3"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/18/1"
                      }
                    ],
                    "severity": [
                      {
                        "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H",
                        "type": "CVSS_V3"
                      }
                    ],
                    "summary": "Incomplete fix for Apache Log4j vulnerability",
                    "withdrawn": false
                  },
                  {
                    "affected": [
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.0-beta7"
                              },
                              {
                                "fixed": "2.3.2"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.0",
                          "2.0-beta7",
                          "2.0-beta8",
                          "2.0-beta9",
                          "2.0-rc1",
                          "2.0-rc2",
                          "2.0.1",
                          "2.0.2",
                          "2.1",
                          "2.2",
                          "2.3",
                          "2.3.1"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.4"
                              },
                              {
                                "fixed": "2.12.4"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.10.0",
                          "2.11.0",
                          "2.11.1",
                          "2.11.2",
                          "2.12.0",
                          "2.12.1",
                          "2.12.2",
                          "2.12.3",
                          "2.4",
                          "2.4.1",
                          "2.5",
                          "2.6",
                          "2.6.1",
                          "2.6.2",
                          "2.7",
                          "2.8",
                          "2.8.1",
                          "2.8.2",
                          "2.9.0",
                          "2.9.1"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.13.0"
                              },
                              {
                                "fixed": "2.17.1"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.13.0",
                          "2.13.1",
                          "2.13.2",
                          "2.13.3",
                          "2.14.0",
                          "2.14.1",
                          "2.15.0",
                          "2.16.0",
                          "2.17.0"
                        ]
                      }
                    ],
                    "aliases": [
                      "CVE-2021-44832"
                    ],
                    "fixed_versions": [
                      "2.3.2",
                      "2.12.4",
                      "2.17.1"
                    ],
                    "id": "GHSA-8489-44mv-ggj8",
                    "max_severity": "medium",
                    "modified": "2026-06-09T10:45:14.253296471Z",
                    "published": "2022-01-04T16:14:20Z",
                    "references": [
                      {
                        "type": "ADVISORY",
                        "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44832"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf"
                      },
                      {
                        "type": "PACKAGE",
                        "url": "https://github.com/apache/logging-log4j2"
                      },
                      {
                        "type": "WEB",
                        "url": "https://issues.apache.org/jira/browse/LOG4J2-3293"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC"
                      },
                      {
                        "type": "WEB",
                        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                      },
                      {
                        "type": "WEB",
                        "url": "https://security.netapp.com/advisory/ntap-20220104-0001"
                      },
                      {
                        "type": "WEB",
                        "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/28/1"
                      }
                    ],
                    "severity": [
                      {
                        "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "type": "CVSS_V3"
                      }
                    ],
                    "summary": "Improper Input Validation and Injection in Apache Log4j2",
                    "withdrawn": false
                  },
                  {
                    "affected": [
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.13.0"
                              },
                              {
                                "fixed": "2.15.0"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.13.0",
                          "2.13.1",
                          "2.13.2",
                          "2.13.3",
                          "2.14.0",
                          "2.14.1"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.0-beta9"
                              },
                              {
                                "fixed": "2.3.1"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.0",
                          "2.0-beta9",
                          "2.0-rc1",
                          "2.0-rc2",
                          "2.0.1",
                          "2.0.2",
                          "2.1",
                          "2.2",
                          "2.3"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.4"
                              },
                              {
                                "fixed": "2.12.2"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.10.0",
                          "2.11.0",
                          "2.11.1",
                          "2.11.2",
                          "2.12.0",
                          "2.12.1",
                          "2.4",
                          "2.4.1",
                          "2.5",
                          "2.6",
                          "2.6.1",
                          "2.6.2",
                          "2.7",
                          "2.8",
                          "2.8.1",
                          "2.8.2",
                          "2.9.0",
                          "2.9.1"
                        ]
                      }
                    ],
                    "aliases": [
                      "CVE-2021-44228"
                    ],
                    "fixed_versions": [
                      "2.15.0",
                      "2.3.1",
                      "2.12.2"
                    ],
                    "id": "GHSA-jfh8-c2jp-5v3q",
                    "kev": {
                      "cve_id": "CVE-2021-44228",
                      "cwes": [
                        "CWE-20",
                        "CWE-400",
                        "CWE-502"
                      ],
                      "date_added": "2021-12-10",
                      "due_date": "2021-12-24",
                      "known_ransomware_campaign_use": "Known",
                      "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
                      "product": "Log4j2",
                      "required_action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
                      "short_description": "Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.",
                      "vendor_project": "Apache",
                      "vulnerability_name": "Apache Log4j2 Remote Code Execution Vulnerability"
                    },
                    "max_severity": "critical",
                    "modified": "2025-10-22T19:37:02.616807Z",
                    "published": "2021-12-10T00:40:56Z",
                    "references": [
                      {
                        "type": "ADVISORY",
                        "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/apache/logging-log4j2/pull/608"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/github/advisory-database/pull/5501"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032"
                      },
                      {
                        "type": "WEB",
                        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                      },
                      {
                        "type": "WEB",
                        "url": "https://seclists.org/fulldisclosure/2022/Dec/2"
                      },
                      {
                        "type": "WEB",
                        "url": "https://seclists.org/fulldisclosure/2022/Jul/11"
                      },
                      {
                        "type": "WEB",
                        "url": "https://seclists.org/fulldisclosure/2022/Mar/23"
                      },
                      {
                        "type": "WEB",
                        "url": "https://security.netapp.com/advisory/ntap-20211210-0007"
                      },
                      {
                        "type": "WEB",
                        "url": "https://support.apple.com/kb/HT213189"
                      },
                      {
                        "type": "WEB",
                        "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                      },
                      {
                        "type": "WEB",
                        "url": "https://twitter.com/kurtseifried/status/1469345530182455296"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.debian.org/security/2021/dsa-5020"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.kb.cert.org/vuls/id/930724"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf"
                      },
                      {
                        "type": "ADVISORY",
                        "url": "https://github.com/advisories/GHSA-7rjr-3q55-vv33"
                      },
                      {
                        "type": "PACKAGE",
                        "url": "https://github.com/apache/logging-log4j2"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/cisagov/log4j-affected-db"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/tangxiaofeng7/apache-log4j-poc"
                      },
                      {
                        "type": "WEB",
                        "url": "https://issues.apache.org/jira/browse/LOG4J2-3198"
                      },
                      {
                        "type": "WEB",
                        "url": "https://issues.apache.org/jira/browse/LOG4J2-3201"
                      },
                      {
                        "type": "WEB",
                        "url": "https://issues.apache.org/jira/browse/LOG4J2-3214"
                      },
                      {
                        "type": "WEB",
                        "url": "https://issues.apache.org/jira/browse/LOG4J2-3221"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/changes-report.html#a2.15.0"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/manual/lookups.html#JndiLookup"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/manual/migration.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/security.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"
                      },
                      {
                        "type": "WEB",
                        "url": "http://seclists.org/fulldisclosure/2022/Dec/2"
                      },
                      {
                        "type": "WEB",
                        "url": "http://seclists.org/fulldisclosure/2022/Jul/11"
                      },
                      {
                        "type": "WEB",
                        "url": "http://seclists.org/fulldisclosure/2022/Mar/23"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/10/1"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/10/2"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/10/3"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/13/1"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/13/2"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/14/4"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/15/3"
                      }
                    ],
                    "severity": [
                      {
                        "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H",
                        "type": "CVSS_V3"
                      }
                    ],
                    "summary": "Remote code injection in Log4j",
                    "withdrawn": false
                  },
                  {
                    "affected": [
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.4.0"
                              },
                              {
                                "fixed": "2.12.3"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.10.0",
                          "2.11.0",
                          "2.11.1",
                          "2.11.2",
                          "2.12.0",
                          "2.12.1",
                          "2.12.2",
                          "2.4",
                          "2.4.1",
                          "2.5",
                          "2.6",
                          "2.6.1",
                          "2.6.2",
                          "2.7",
                          "2.8",
                          "2.8.1",
                          "2.8.2",
                          "2.9.0",
                          "2.9.1"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.13.0"
                              },
                              {
                                "fixed": "2.17.0"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.13.0",
                          "2.13.1",
                          "2.13.2",
                          "2.13.3",
                          "2.14.0",
                          "2.14.1",
                          "2.15.0",
                          "2.16.0"
                        ]
                      },
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "0"
                              },
                              {
                                "fixed": "2.3.1"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.0",
                          "2.0-alpha1",
                          "2.0-alpha2",
                          "2.0-beta1",
                          "2.0-beta2",
                          "2.0-beta3",
                          "2.0-beta4",
                          "2.0-beta5",
                          "2.0-beta6",
                          "2.0-beta7",
                          "2.0-beta8",
                          "2.0-beta9",
                          "2.0-rc1",
                          "2.0-rc2",
                          "2.0.1",
                          "2.0.2",
                          "2.1",
                          "2.2",
                          "2.3"
                        ]
                      }
                    ],
                    "aliases": [
                      "CVE-2021-45105"
                    ],
                    "fixed_versions": [
                      "2.12.3",
                      "2.17.0",
                      "2.3.1"
                    ],
                    "id": "GHSA-p6xc-xr62-6r2g",
                    "max_severity": "high",
                    "modified": "2026-06-09T10:30:14.432177927Z",
                    "published": "2021-12-18T18:00:07Z",
                    "references": [
                      {
                        "type": "ADVISORY",
                        "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45105"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1541"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.kb.cert.org/vuls/id/930724"
                      },
                      {
                        "type": "WEB",
                        "url": "https://www.debian.org/security/2021/dsa-5024"
                      },
                      {
                        "type": "WEB",
                        "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                      },
                      {
                        "type": "WEB",
                        "url": "https://security.netapp.com/advisory/ntap-20211218-0001"
                      },
                      {
                        "type": "WEB",
                        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                      },
                      {
                        "type": "WEB",
                        "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/security.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00017.html"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/19/1"
                      }
                    ],
                    "severity": [
                      {
                        "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
                        "type": "CVSS_V3"
                      }
                    ],
                    "summary": "Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion",
                    "withdrawn": false
                  },
                  {
                    "affected": [
                      {
                        "package": {
                          "ecosystem": "Maven",
                          "name": "org.apache.logging.log4j:log4j-core",
                          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
                        },
                        "ranges": [
                          {
                            "events": [
                              {
                                "introduced": "2.0-beta9"
                              },
                              {
                                "fixed": "2.25.3"
                              }
                            ],
                            "type": "ECOSYSTEM"
                          }
                        ],
                        "severity": [],
                        "versions": [
                          "2.0",
                          "2.0-beta9",
                          "2.0-rc1",
                          "2.0-rc2",
                          "2.0.1",
                          "2.0.2",
                          "2.1",
                          "2.10.0",
                          "2.11.0",
                          "2.11.1",
                          "2.11.2",
                          "2.12.0",
                          "2.12.1",
                          "2.12.2",
                          "2.12.3",
                          "2.12.4",
                          "2.13.0",
                          "2.13.1",
                          "2.13.2",
                          "2.13.3",
                          "2.14.0",
                          "2.14.1",
                          "2.15.0",
                          "2.16.0",
                          "2.17.0",
                          "2.17.1",
                          "2.17.2",
                          "2.18.0",
                          "2.19.0",
                          "2.2",
                          "2.20.0",
                          "2.21.0",
                          "2.21.1",
                          "2.22.0",
                          "2.22.1",
                          "2.23.0",
                          "2.23.1",
                          "2.24.0",
                          "2.24.1",
                          "2.24.2",
                          "2.24.3",
                          "2.25.0",
                          "2.25.1",
                          "2.25.2",
                          "2.3",
                          "2.3.1",
                          "2.3.2",
                          "2.4",
                          "2.4.1",
                          "2.5",
                          "2.6",
                          "2.6.1",
                          "2.6.2",
                          "2.7",
                          "2.8",
                          "2.8.1",
                          "2.8.2",
                          "2.9.0",
                          "2.9.1"
                        ]
                      }
                    ],
                    "aliases": [
                      "CVE-2025-68161"
                    ],
                    "fixed_versions": [
                      "2.25.3"
                    ],
                    "id": "GHSA-vc5p-v9hr-52mj",
                    "max_severity": "medium",
                    "modified": "2026-02-04T03:10:00.616806Z",
                    "published": "2025-12-18T21:31:44Z",
                    "references": [
                      {
                        "type": "ADVISORY",
                        "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68161"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/apache/logging-log4j2/pull/4002"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578"
                      },
                      {
                        "type": "WEB",
                        "url": "https://github.com/apache/logging-log4j2"
                      },
                      {
                        "type": "WEB",
                        "url": "https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/cyclonedx/vdr.xml"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName"
                      },
                      {
                        "type": "WEB",
                        "url": "https://logging.apache.org/security.html#CVE-2025-68161"
                      },
                      {
                        "type": "WEB",
                        "url": "http://www.openwall.com/lists/oss-security/2025/12/18/1"
                      }
                    ],
                    "severity": [
                      {
                        "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N",
                        "type": "CVSS_V4"
                      }
                    ],
                    "summary": "Apache Log4j does not verify the TLS hostname in its Socket Appender",
                    "withdrawn": false
                  }
                ],
                "input": {
                  "ecosystem": "maven",
                  "name": "org.apache.logging.log4j/log4j-core",
                  "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1",
                  "version": "2.14.1"
                },
                "status": "vulnerabilities_found",
                "summary": {
                  "finding_count": 7,
                  "kev_count": 2,
                  "max_severity": "critical"
                }
              }
            ],
            "retrieved_at": "2026-08-02T00:00:00Z",
            "schema_version": "dependency-risk-v1",
            "source": {
              "cisa_kev": {
                "catalog_version": "2026.07.29",
                "date_released": "2026-07-29T18:45:59.5809Z",
                "name": "Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog",
                "retrieved_at": "2026-08-02T00:00:00Z"
              },
              "osv": {
                "name": "OSV.dev"
              }
            },
            "stale": false,
            "warnings": []
          },
          "type": "json"
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "properties": {
          "input": {
            "additionalProperties": false,
            "properties": {
              "body": {
                "additionalProperties": false,
                "properties": {
                  "document": {
                    "additionalProperties": false,
                    "description": "Bounded CycloneDX JSON 1.5 document containing at least one versioned-purl component",
                    "properties": {
                      "bomFormat": {
                        "const": "CycloneDX",
                        "description": "Required CycloneDX format marker",
                        "type": "string"
                      },
                      "components": {
                        "description": "Bounded components with canonical versioned purls. The complete OSV result must contain no page token and at most eight distinct vulnerability IDs for V1 enrichment.",
                        "items": {
                          "additionalProperties": false,
                          "description": "Minimal supported CycloneDX component shape for agent-generated requests",
                          "properties": {
                            "name": {
                              "description": "Optional public component name retained only for component-identity conflict checks",
                              "maxLength": 16384,
                              "minLength": 1,
                              "type": "string"
                            },
                            "purl": {
                              "description": "Required canonical package URL containing an embedded exact version",
                              "maxLength": 2048,
                              "minLength": 1,
                              "type": "string"
                            },
                            "type": {
                              "description": "Optional CycloneDX component type retained only for component-identity conflict checks",
                              "maxLength": 16384,
                              "minLength": 1,
                              "type": "string"
                            },
                            "version": {
                              "description": "Optional exact component version; when present it must equal the purl version",
                              "maxLength": 256,
                              "minLength": 1,
                              "type": "string"
                            }
                          },
                          "required": [
                            "purl"
                          ],
                          "type": "object"
                        },
                        "maxItems": 200,
                        "minItems": 1,
                        "type": "array"
                      },
                      "specVersion": {
                        "const": "1.5",
                        "description": "Supported CycloneDX JSON specification version",
                        "type": "string"
                      }
                    },
                    "required": [
                      "bomFormat",
                      "specVersion",
                      "components"
                    ],
                    "type": "object"
                  }
                },
                "required": [
                  "document"
                ],
                "type": "object"
              },
              "bodyType": {
                "enum": [
                  "json",
                  "form-data",
                  "text"
                ],
                "type": "string"
              },
              "method": {
                "enum": [
                  "POST"
                ],
                "type": "string"
              },
              "type": {
                "const": "http",
                "type": "string"
              }
            },
            "required": [
              "type",
              "method",
              "bodyType",
              "body"
            ],
            "type": "object"
          },
          "output": {
            "properties": {
              "example": {
                "additionalProperties": false,
                "description": "Complete transactional Dependency Risk response, limited to the native budget reserved below the 512 KiB deployed wire ceiling",
                "properties": {
                  "_atlas": {
                    "additionalProperties": false,
                    "description": "Atlas documentation and related-route metadata added after deployment",
                    "properties": {
                      "docs": {
                        "description": "Documentation URL for this bridge",
                        "format": "uri",
                        "maxLength": 512,
                        "type": "string"
                      },
                      "related": {
                        "description": "Bounded related Atlas routes",
                        "items": {
                          "additionalProperties": false,
                          "description": "One related Atlas route",
                          "properties": {
                            "bridge": {
                              "description": "Related bridge name",
                              "maxLength": 64,
                              "type": "string"
                            },
                            "docs": {
                              "description": "Related bridge documentation URL",
                              "format": "uri",
                              "maxLength": 512,
                              "type": "string"
                            },
                            "summary": {
                              "description": "Short capability summary",
                              "maxLength": 256,
                              "type": "string"
                            },
                            "url": {
                              "description": "Related route URL",
                              "format": "uri",
                              "maxLength": 512,
                              "type": "string"
                            }
                          },
                          "required": [
                            "bridge",
                            "url",
                            "docs",
                            "summary"
                          ],
                          "type": "object"
                        },
                        "maxItems": 3,
                        "type": "array"
                      }
                    },
                    "required": [
                      "docs"
                    ],
                    "type": "object"
                  },
                  "operation": {
                    "const": "sbom-check",
                    "description": "Stable route operation identifier",
                    "type": "string"
                  },
                  "partial": {
                    "description": "True only when at least one complete item succeeded and another detail lookup transiently failed",
                    "type": "boolean"
                  },
                  "results": {
                    "description": "Complete or explicitly failed results in original caller input order, including duplicate positions; all items collectively reference at most eight distinct OSV IDs",
                    "items": {
                      "additionalProperties": false,
                      "description": "One position-preserving package result",
                      "oneOf": [
                        {
                          "not": {
                            "required": [
                              "error_code"
                            ]
                          },
                          "properties": {
                            "status": {
                              "description": "A complete named-source conclusion requires summary and omits error_code",
                              "enum": [
                                "no_known_vulnerabilities",
                                "vulnerabilities_found"
                              ]
                            }
                          },
                          "required": [
                            "summary"
                          ]
                        },
                        {
                          "not": {
                            "required": [
                              "summary"
                            ]
                          },
                          "properties": {
                            "status": {
                              "const": "query_failed",
                              "description": "An incomplete upstream result requires error_code and omits summary so it cannot resemble a risk conclusion"
                            }
                          },
                          "required": [
                            "error_code"
                          ]
                        }
                      ],
                      "properties": {
                        "error_code": {
                          "const": "upstream_error",
                          "description": "Generic non-sensitive code present only when status is query_failed",
                          "type": "string"
                        },
                        "findings": {
                          "description": "Complete findings for this exact input; collectively all response items reference at most eight distinct OSV IDs; always [] for no_known_vulnerabilities or query_failed",
                          "items": {
                            "additionalProperties": false,
                            "description": "One complete normalized OSV vulnerability finding, limited to 48 KiB after JSON encoding, with optional exact CISA KEV enrichment",
                            "properties": {
                              "affected": {
                                "description": "Bounded OSV affected package/range/event data in source order",
                                "items": {
                                  "additionalProperties": false,
                                  "description": "One OSV affected package entry retained in source order",
                                  "properties": {
                                    "package": {
                                      "additionalProperties": false,
                                      "description": "Exact affected package identity published by OSV",
                                      "properties": {
                                        "ecosystem": {
                                          "description": "Exact OSV ecosystem identifier",
                                          "type": "string"
                                        },
                                        "name": {
                                          "description": "Exact package name published by OSV",
                                          "type": "string"
                                        },
                                        "purl": {
                                          "description": "Package URL published by OSV when supplied",
                                          "type": "string"
                                        }
                                      },
                                      "type": "object"
                                    },
                                    "ranges": {
                                      "description": "Affected ranges retained in OSV source order",
                                      "items": {
                                        "additionalProperties": false,
                                        "description": "One affected version range published by OSV",
                                        "properties": {
                                          "events": {
                                            "description": "Ordered OSV range events; the bridge does not infer ecosystem version ordering",
                                            "items": {
                                              "additionalProperties": false,
                                              "description": "One OSV range event; exactly one event field is normally supplied by the source",
                                              "properties": {
                                                "fixed": {
                                                  "description": "OSV range event explicitly marking a fixed version",
                                                  "type": "string"
                                                },
                                                "introduced": {
                                                  "description": "OSV range event marking an introduced version",
                                                  "type": "string"
                                                },
                                                "last_affected": {
                                                  "description": "OSV range event marking the last affected version",
                                                  "type": "string"
                                                },
                                                "limit": {
                                                  "description": "OSV range event upper limit when supplied",
                                                  "type": "string"
                                                }
                                              },
                                              "type": "object"
                                            },
                                            "type": "array"
                                          },
                                          "repo": {
                                            "description": "Repository identifier published by OSV for a GIT range",
                                            "type": "string"
                                          },
                                          "type": {
                                            "description": "OSV range type such as SEMVER, ECOSYSTEM, or GIT",
                                            "type": "string"
                                          }
                                        },
                                        "required": [
                                          "type",
                                          "events"
                                        ],
                                        "type": "object"
                                      },
                                      "type": "array"
                                    },
                                    "severity": {
                                      "description": "Severity vectors attached to this affected package entry",
                                      "items": {
                                        "additionalProperties": false,
                                        "description": "One severity vector exactly as published by OSV",
                                        "properties": {
                                          "score": {
                                            "description": "Original published vector; malformed or mismatched vectors are retained but score as unknown",
                                            "type": "string"
                                          },
                                          "type": {
                                            "description": "OSV-declared score type such as CVSS_V3",
                                            "type": "string"
                                          }
                                        },
                                        "required": [
                                          "type",
                                          "score"
                                        ],
                                        "type": "object"
                                      },
                                      "type": "array"
                                    },
                                    "versions": {
                                      "description": "Affected versions explicitly enumerated by OSV",
                                      "items": {
                                        "type": "string"
                                      },
                                      "type": "array"
                                    }
                                  },
                                  "required": [
                                    "package",
                                    "ranges",
                                    "versions",
                                    "severity"
                                  ],
                                  "type": "object"
                                },
                                "type": "array"
                              },
                              "aliases": {
                                "description": "Deduplicated lexical aliases published by OSV",
                                "items": {
                                  "type": "string"
                                },
                                "type": "array"
                              },
                              "fixed_versions": {
                                "description": "Only explicit fixed events for the matching package, deduplicated in OSV source order; [] means OSV supplied no fixed event, not that no fix exists",
                                "items": {
                                  "type": "string"
                                },
                                "type": "array"
                              },
                              "id": {
                                "description": "Authoritative OSV record identifier",
                                "type": "string"
                              },
                              "kev": {
                                "additionalProperties": false,
                                "description": "Exact CISA KEV match on a syntactically valid CVE ID or alias; omitted rather than null when no exact match exists",
                                "properties": {
                                  "cve_id": {
                                    "description": "Exact CVE identifier matched in the CISA KEV catalog",
                                    "type": "string"
                                  },
                                  "cwes": {
                                    "description": "CWE identifiers published by CISA",
                                    "items": {
                                      "type": "string"
                                    },
                                    "type": "array"
                                  },
                                  "date_added": {
                                    "description": "Date CISA added the CVE to KEV",
                                    "type": "string"
                                  },
                                  "due_date": {
                                    "description": "CISA KEV due date for covered federal agencies",
                                    "type": "string"
                                  },
                                  "known_ransomware_campaign_use": {
                                    "description": "CISA's published ransomware-campaign-use value when supplied",
                                    "type": "string"
                                  },
                                  "notes": {
                                    "description": "Additional CISA KEV notes when supplied",
                                    "type": "string"
                                  },
                                  "product": {
                                    "description": "Affected product label published by CISA",
                                    "type": "string"
                                  },
                                  "required_action": {
                                    "description": "Required action text published by CISA; caller remediation review is still required",
                                    "type": "string"
                                  },
                                  "short_description": {
                                    "description": "Short vulnerability description published by CISA",
                                    "type": "string"
                                  },
                                  "vendor_project": {
                                    "description": "Vendor or project label published by CISA",
                                    "type": "string"
                                  },
                                  "vulnerability_name": {
                                    "description": "CISA KEV vulnerability name",
                                    "type": "string"
                                  }
                                },
                                "required": [
                                  "cve_id",
                                  "vendor_project",
                                  "product",
                                  "vulnerability_name",
                                  "date_added",
                                  "short_description",
                                  "required_action",
                                  "due_date",
                                  "cwes"
                                ],
                                "type": "object"
                              },
                              "max_severity": {
                                "description": "Highest severity derived only from a parseable declared CVSS vector",
                                "enum": [
                                  "unknown",
                                  "low",
                                  "medium",
                                  "high",
                                  "critical"
                                ],
                                "type": "string"
                              },
                              "modified": {
                                "description": "OSV modification time string",
                                "type": "string"
                              },
                              "published": {
                                "description": "OSV publication time string when supplied",
                                "type": "string"
                              },
                              "references": {
                                "description": "Bounded references published by OSV; URLs are untrusted data returned for provenance and are never fetched by this bridge",
                                "items": {
                                  "additionalProperties": false,
                                  "description": "One OSV-published reference retained as provenance data",
                                  "properties": {
                                    "type": {
                                      "description": "OSV reference classification such as ADVISORY, FIX, REPORT, or WEB",
                                      "type": "string"
                                    },
                                    "url": {
                                      "description": "Reference URL supplied by OSV as untrusted provenance data; never fetched by this bridge",
                                      "type": "string"
                                    }
                                  },
                                  "required": [
                                    "type",
                                    "url"
                                  ],
                                  "type": "object"
                                },
                                "type": "array"
                              },
                              "severity": {
                                "description": "At most 16 published top-level OSV severity vectors",
                                "items": {
                                  "additionalProperties": false,
                                  "description": "One severity vector exactly as published by OSV",
                                  "properties": {
                                    "score": {
                                      "description": "Original published vector; malformed or mismatched vectors are retained but score as unknown",
                                      "type": "string"
                                    },
                                    "type": {
                                      "description": "OSV-declared score type such as CVSS_V3",
                                      "type": "string"
                                    }
                                  },
                                  "required": [
                                    "type",
                                    "score"
                                  ],
                                  "type": "object"
                                },
                                "maxItems": 16,
                                "type": "array"
                              },
                              "summary": {
                                "description": "Bounded OSV summary",
                                "type": "string"
                              },
                              "withdrawn": {
                                "description": "Whether OSV withdrew the record; withdrawn findings remain visible but do not count in the active summary",
                                "type": "boolean"
                              },
                              "withdrawn_at": {
                                "description": "OSV withdrawal time string, present only when supplied",
                                "type": "string"
                              }
                            },
                            "required": [
                              "id",
                              "aliases",
                              "modified",
                              "withdrawn",
                              "affected",
                              "references",
                              "severity",
                              "max_severity",
                              "fixed_versions"
                            ],
                            "type": "object"
                          },
                          "maxItems": 8,
                          "type": "array"
                        },
                        "input": {
                          "additionalProperties": false,
                          "description": "Canonical exact package/version identity",
                          "properties": {
                            "ecosystem": {
                              "description": "Exact package ecosystem; purl types remain canonical lowercase identifiers",
                              "type": "string"
                            },
                            "name": {
                              "description": "Exact package-manager name",
                              "type": "string"
                            },
                            "purl": {
                              "description": "Canonical input purl when the caller used purl form; otherwise omitted",
                              "type": "string"
                            },
                            "version": {
                              "description": "Exact queried package version",
                              "type": "string"
                            }
                          },
                          "required": [
                            "ecosystem",
                            "name",
                            "version"
                          ],
                          "type": "object"
                        },
                        "status": {
                          "description": "Named-source conclusion: query_failed is explicit incompleteness and never a clean result",
                          "enum": [
                            "no_known_vulnerabilities",
                            "vulnerabilities_found",
                            "query_failed"
                          ],
                          "type": "string"
                        },
                        "summary": {
                          "additionalProperties": false,
                          "description": "Summary of active non-withdrawn findings",
                          "properties": {
                            "finding_count": {
                              "description": "Active non-withdrawn finding count",
                              "maximum": 8,
                              "minimum": 0,
                              "type": "integer"
                            },
                            "kev_count": {
                              "description": "Active findings with an exact KEV CVE match",
                              "maximum": 8,
                              "minimum": 0,
                              "type": "integer"
                            },
                            "max_severity": {
                              "description": "Highest parseable published CVSS severity among active findings",
                              "enum": [
                                "unknown",
                                "low",
                                "medium",
                                "high",
                                "critical"
                              ],
                              "type": "string"
                            }
                          },
                          "required": [
                            "finding_count",
                            "kev_count",
                            "max_severity"
                          ],
                          "type": "object"
                        }
                      },
                      "required": [
                        "input",
                        "status",
                        "findings"
                      ],
                      "type": "object"
                    },
                    "maxItems": 200,
                    "type": "array"
                  },
                  "retrieved_at": {
                    "description": "UTC time this bridge completed the response; this is not an OSV publication or modification time",
                    "format": "date-time",
                    "type": "string"
                  },
                  "schema_version": {
                    "const": "dependency-risk-v1",
                    "description": "Version of the normalized Dependency Risk response contract",
                    "type": "string"
                  },
                  "source": {
                    "additionalProperties": false,
                    "description": "Named public sources and the exact CISA KEV snapshot used for this response",
                    "properties": {
                      "cisa_kev": {
                        "additionalProperties": false,
                        "description": "Validated CISA Known Exploited Vulnerabilities snapshot used for exact CVE enrichment",
                        "properties": {
                          "catalog_version": {
                            "description": "Catalog version published in the validated CISA feed",
                            "type": "string"
                          },
                          "date_released": {
                            "description": "Release time published in the validated CISA feed",
                            "type": "string"
                          },
                          "name": {
                            "const": "Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog",
                            "description": "Official CISA KEV source name",
                            "type": "string"
                          },
                          "retrieved_at": {
                            "description": "UTC time this exact validated KEV snapshot was retrieved",
                            "format": "date-time",
                            "type": "string"
                          }
                        },
                        "required": [
                          "name",
                          "catalog_version",
                          "date_released",
                          "retrieved_at"
                        ],
                        "type": "object"
                      },
                      "osv": {
                        "additionalProperties": false,
                        "description": "OSV source identity; individual finding times carry record publication and modification semantics",
                        "properties": {
                          "name": {
                            "const": "OSV.dev",
                            "description": "Official OSV.dev vulnerability record aggregator",
                            "type": "string"
                          }
                        },
                        "required": [
                          "name"
                        ],
                        "type": "object"
                      }
                    },
                    "required": [
                      "osv",
                      "cisa_kev"
                    ],
                    "type": "object"
                  },
                  "stale": {
                    "description": "True only when a prior validated CISA KEV snapshot is served after refresh failure; OSV result completeness is never silently marked stale",
                    "type": "boolean"
                  },
                  "warnings": {
                    "description": "Freshness and interpretation warnings; always [] when none",
                    "items": {
                      "description": "Bounded warning intended for caller action or interpretation",
                      "type": "string"
                    },
                    "type": "array"
                  }
                },
                "required": [
                  "operation",
                  "schema_version",
                  "source",
                  "retrieved_at",
                  "stale",
                  "warnings",
                  "results",
                  "partial"
                ],
                "type": "object"
              },
              "type": {
                "type": "string"
              }
            },
            "required": [
              "type"
            ],
            "type": "object"
          }
        },
        "required": [
          "input"
        ],
        "type": "object"
      },
      "tags": [
        "cyclonedx-sbom-check",
        "osv",
        "cve",
        "cisa-kev",
        "software-supply-chain"
      ]
    }
  },
  "tags": [
    "bazaar"
  ],
  "sourceHost": "dependency-risk.use.x402atlas.com",
  "lastUpdated": "2026-09-15T06:32:25.173Z",
  "quality": {
    "calls30d": 2,
    "uniquePayers30d": 1,
    "lastCalledAt": "2026-09-15T06:32:23.518Z"
  },
  "liveness": {},
  "verified": false,
  "featured": false,
  "provider": {
    "host": "dependency-risk.use.x402atlas.com",
    "manifest_name": "dependency-risk.use.x402atlas.com",
    "source": "cdp-mirror",
    "source_manifest_url": "https://api.cdp.coinbase.com/platform/v2/x402/discovery/resources",
    "submitted_at": "2026-09-18T22:00:31.484Z"
  }
}