Package vulnerability check — check one exact open-source dependency version or purl again
Package vulnerability check — check one exact open-source dependency version or purl against OSV, enrich CVE matches with CISA KEV known-exploited signals, and report fixes, severity, and provenance.
5000 (raw units)
price
2
calls / 30d
1
unique payers
2026-09-15
updated
Provider
dependency-risk.use.x402atlas.com · discovered, not yet claimed by its owner
Payment (x402 accepts[])
[
{
"scheme": "exact",
"network": "eip155:8453",
"payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"amount": "5000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:137",
"payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"amount": "5000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:42161",
"payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"amount": "5000",
"maxTimeoutSeconds": 300
}
]Output schema
{
"bazaar": {
"category": "security",
"info": {
"input": {
"body": {
"purl": "pkg:maven/org.apache.logging.log4j/[email protected]"
},
"bodyType": "json",
"method": "POST",
"type": "http"
},
"output": {
"example": {
"findings": [
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.0-alpha1"
},
{
"fixed": "2.25.4"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.0",
"2.0-alpha1",
"2.0-alpha2",
"2.0-beta1",
"2.0-beta2",
"2.0-beta3",
"2.0-beta4",
"2.0-beta5",
"2.0-beta6",
"2.0-beta7",
"2.0-beta8",
"2.0-beta9",
"2.0-rc1",
"2.0-rc2",
"2.0.1",
"2.0.2",
"2.1",
"2.10.0",
"2.11.0",
"2.11.1",
"2.11.2",
"2.12.0",
"2.12.1",
"2.12.2",
"2.12.3",
"2.12.4",
"2.13.0",
"2.13.1",
"2.13.2",
"2.13.3",
"2.14.0",
"2.14.1",
"2.15.0",
"2.16.0",
"2.17.0",
"2.17.1",
"2.17.2",
"2.18.0",
"2.19.0",
"2.2",
"2.20.0",
"2.21.0",
"2.21.1",
"2.22.0",
"2.22.1",
"2.23.0",
"2.23.1",
"2.24.0",
"2.24.1",
"2.24.2",
"2.24.3",
"2.25.0",
"2.25.1",
"2.25.2",
"2.25.3",
"2.3",
"2.3.1",
"2.3.2",
"2.4",
"2.4.1",
"2.5",
"2.6",
"2.6.1",
"2.6.2",
"2.7",
"2.8",
"2.8.1",
"2.8.2",
"2.9.0",
"2.9.1"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.0-alpha1"
},
{
"last_affected": "3.0.0-beta3"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"3.0.0-alpha1",
"3.0.0-beta1",
"3.0.0-beta2",
"3.0.0-beta3"
]
}
],
"aliases": [
"CVE-2026-34480"
],
"fixed_versions": [
"2.25.4"
],
"id": "GHSA-3pxv-7cmr-fjr4",
"max_severity": "medium",
"modified": "2026-04-16T11:29:10.536806482Z",
"published": "2026-04-10T18:31:17Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34480"
},
{
"type": "WEB",
"url": "https://github.com/apache/logging-log4j2/pull/4077"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/logging-log4j2"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb"
},
{
"type": "WEB",
"url": "https://logging.apache.org/cyclonedx/vdr.xml"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout"
},
{
"type": "WEB",
"url": "https://logging.apache.org/security.html#CVE-2026-34480"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2026/04/10/9"
}
],
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N",
"type": "CVSS_V4"
}
],
"summary": "Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters",
"withdrawn": false
},
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.12.0"
},
{
"fixed": "2.25.4"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.12.0",
"2.12.1",
"2.12.2",
"2.12.3",
"2.12.4",
"2.13.0",
"2.13.1",
"2.13.2",
"2.13.3",
"2.14.0",
"2.14.1",
"2.15.0",
"2.16.0",
"2.17.0",
"2.17.1",
"2.17.2",
"2.18.0",
"2.19.0",
"2.20.0",
"2.21.0",
"2.21.1",
"2.22.0",
"2.22.1",
"2.23.0",
"2.23.1",
"2.24.0",
"2.24.1",
"2.24.2",
"2.24.3",
"2.25.0",
"2.25.1",
"2.25.2",
"2.25.3"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.0-alpha1"
},
{
"last_affected": "3.0.0-beta3"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"3.0.0-alpha1",
"3.0.0-beta1",
"3.0.0-beta2",
"3.0.0-beta3"
]
}
],
"aliases": [
"CVE-2026-34477"
],
"fixed_versions": [
"2.25.4"
],
"id": "GHSA-6hg6-v5c8-fphq",
"max_severity": "medium",
"modified": "2026-04-17T12:29:10.521430176Z",
"published": "2026-04-10T18:31:17Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34477"
},
{
"type": "WEB",
"url": "https://github.com/apache/logging-log4j2/pull/4075"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/logging-log4j2"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4"
},
{
"type": "WEB",
"url": "https://logging.apache.org/cyclonedx/vdr.xml"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName"
},
{
"type": "WEB",
"url": "https://logging.apache.org/security.html#CVE-2026-34477"
}
],
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N",
"type": "CVSS_V4"
}
],
"summary": "Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration",
"withdrawn": false
},
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.13.0"
},
{
"fixed": "2.16.0"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.13.0",
"2.13.1",
"2.13.2",
"2.13.3",
"2.14.0",
"2.14.1",
"2.15.0"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.12.2"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.0",
"2.0-alpha1",
"2.0-alpha2",
"2.0-beta1",
"2.0-beta2",
"2.0-beta3",
"2.0-beta4",
"2.0-beta5",
"2.0-beta6",
"2.0-beta7",
"2.0-beta8",
"2.0-beta9",
"2.0-rc1",
"2.0-rc2",
"2.0.1",
"2.0.2",
"2.1",
"2.10.0",
"2.11.0",
"2.11.1",
"2.11.2",
"2.12.0",
"2.12.1",
"2.2",
"2.3",
"2.3.1",
"2.3.2",
"2.4",
"2.4.1",
"2.5",
"2.6",
"2.6.1",
"2.6.2",
"2.7",
"2.8",
"2.8.1",
"2.8.2",
"2.9.0",
"2.9.1"
]
}
],
"aliases": [
"CVE-2021-45046"
],
"fixed_versions": [
"2.16.0",
"2.12.2"
],
"id": "GHSA-7rjr-3q55-vv33",
"kev": {
"cve_id": "CVE-2021-45046",
"cwes": [
"CWE-917"
],
"date_added": "2023-05-01",
"due_date": "2023-05-22",
"known_ransomware_campaign_use": "Known",
"notes": "https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046",
"product": "Log4j2",
"required_action": "Apply updates per vendor instructions.",
"short_description": "Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.",
"vendor_project": "Apache",
"vulnerability_name": "Apache Log4j2 Deserialization of Untrusted Data Vulnerability"
},
"max_severity": "critical",
"modified": "2025-10-22T19:37:53.742023Z",
"published": "2021-12-14T18:01:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45046"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujan2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2021/12/14/4"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/930724"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2021/dsa-5022"
},
{
"type": "WEB",
"url": "https://www.cve.org/CVERecord?id=CVE-2021-44228"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046"
},
{
"type": "WEB",
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202310-16"
},
{
"type": "WEB",
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
},
{
"type": "WEB",
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/security.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-jfh8-c2jp-5v3q"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/14/4"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/15/3"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/18/1"
}
],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H",
"type": "CVSS_V3"
}
],
"summary": "Incomplete fix for Apache Log4j vulnerability",
"withdrawn": false
},
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.0-beta7"
},
{
"fixed": "2.3.2"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.0",
"2.0-beta7",
"2.0-beta8",
"2.0-beta9",
"2.0-rc1",
"2.0-rc2",
"2.0.1",
"2.0.2",
"2.1",
"2.2",
"2.3",
"2.3.1"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.4"
},
{
"fixed": "2.12.4"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.10.0",
"2.11.0",
"2.11.1",
"2.11.2",
"2.12.0",
"2.12.1",
"2.12.2",
"2.12.3",
"2.4",
"2.4.1",
"2.5",
"2.6",
"2.6.1",
"2.6.2",
"2.7",
"2.8",
"2.8.1",
"2.8.2",
"2.9.0",
"2.9.1"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.13.0"
},
{
"fixed": "2.17.1"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.13.0",
"2.13.1",
"2.13.2",
"2.13.3",
"2.14.0",
"2.14.1",
"2.15.0",
"2.16.0",
"2.17.0"
]
}
],
"aliases": [
"CVE-2021-44832"
],
"fixed_versions": [
"2.3.2",
"2.12.4",
"2.17.1"
],
"id": "GHSA-8489-44mv-ggj8",
"max_severity": "medium",
"modified": "2026-06-09T10:45:14.253296471Z",
"published": "2022-01-04T16:14:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44832"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/logging-log4j2"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/LOG4J2-3293"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC"
},
{
"type": "WEB",
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20220104-0001"
},
{
"type": "WEB",
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujan2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/28/1"
}
],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Improper Input Validation and Injection in Apache Log4j2",
"withdrawn": false
},
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.13.0"
},
{
"fixed": "2.15.0"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.13.0",
"2.13.1",
"2.13.2",
"2.13.3",
"2.14.0",
"2.14.1"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.0-beta9"
},
{
"fixed": "2.3.1"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.0",
"2.0-beta9",
"2.0-rc1",
"2.0-rc2",
"2.0.1",
"2.0.2",
"2.1",
"2.2",
"2.3"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.4"
},
{
"fixed": "2.12.2"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.10.0",
"2.11.0",
"2.11.1",
"2.11.2",
"2.12.0",
"2.12.1",
"2.4",
"2.4.1",
"2.5",
"2.6",
"2.6.1",
"2.6.2",
"2.7",
"2.8",
"2.8.1",
"2.8.2",
"2.9.0",
"2.9.1"
]
}
],
"aliases": [
"CVE-2021-44228"
],
"fixed_versions": [
"2.15.0",
"2.3.1",
"2.12.2"
],
"id": "GHSA-jfh8-c2jp-5v3q",
"kev": {
"cve_id": "CVE-2021-44228",
"cwes": [
"CWE-20",
"CWE-400",
"CWE-502"
],
"date_added": "2021-12-10",
"due_date": "2021-12-24",
"known_ransomware_campaign_use": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
"product": "Log4j2",
"required_action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
"short_description": "Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.",
"vendor_project": "Apache",
"vulnerability_name": "Apache Log4j2 Remote Code Execution Vulnerability"
},
"max_severity": "critical",
"modified": "2025-10-22T19:37:02.616807Z",
"published": "2021-12-10T00:40:56Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
},
{
"type": "WEB",
"url": "https://github.com/apache/logging-log4j2/pull/608"
},
{
"type": "WEB",
"url": "https://github.com/github/advisory-database/pull/5501"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032"
},
{
"type": "WEB",
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
},
{
"type": "WEB",
"url": "https://seclists.org/fulldisclosure/2022/Dec/2"
},
{
"type": "WEB",
"url": "https://seclists.org/fulldisclosure/2022/Jul/11"
},
{
"type": "WEB",
"url": "https://seclists.org/fulldisclosure/2022/Mar/23"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20211210-0007"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT213189"
},
{
"type": "WEB",
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
},
{
"type": "WEB",
"url": "https://twitter.com/kurtseifried/status/1469345530182455296"
},
{
"type": "WEB",
"url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2021/dsa-5020"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/930724"
},
{
"type": "WEB",
"url": "https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujan2022.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-7rjr-3q55-vv33"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/logging-log4j2"
},
{
"type": "WEB",
"url": "https://github.com/cisagov/log4j-affected-db"
},
{
"type": "WEB",
"url": "https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md"
},
{
"type": "WEB",
"url": "https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228"
},
{
"type": "WEB",
"url": "https://github.com/tangxiaofeng7/apache-log4j-poc"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/LOG4J2-3198"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/LOG4J2-3201"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/LOG4J2-3214"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/LOG4J2-3221"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/changes-report.html#a2.15.0"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/manual/lookups.html#JndiLookup"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/manual/migration.html"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/security.html"
},
{
"type": "WEB",
"url": "https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2022/Dec/2"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2022/Jul/11"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2022/Mar/23"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/10/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/10/2"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/10/3"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/13/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/13/2"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/14/4"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/15/3"
}
],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H",
"type": "CVSS_V3"
}
],
"summary": "Remote code injection in Log4j",
"withdrawn": false
},
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.4.0"
},
{
"fixed": "2.12.3"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.10.0",
"2.11.0",
"2.11.1",
"2.11.2",
"2.12.0",
"2.12.1",
"2.12.2",
"2.4",
"2.4.1",
"2.5",
"2.6",
"2.6.1",
"2.6.2",
"2.7",
"2.8",
"2.8.1",
"2.8.2",
"2.9.0",
"2.9.1"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.13.0"
},
{
"fixed": "2.17.0"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.13.0",
"2.13.1",
"2.13.2",
"2.13.3",
"2.14.0",
"2.14.1",
"2.15.0",
"2.16.0"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.3.1"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.0",
"2.0-alpha1",
"2.0-alpha2",
"2.0-beta1",
"2.0-beta2",
"2.0-beta3",
"2.0-beta4",
"2.0-beta5",
"2.0-beta6",
"2.0-beta7",
"2.0-beta8",
"2.0-beta9",
"2.0-rc1",
"2.0-rc2",
"2.0.1",
"2.0.2",
"2.1",
"2.2",
"2.3"
]
}
],
"aliases": [
"CVE-2021-45105"
],
"fixed_versions": [
"2.12.3",
"2.17.0",
"2.3.1"
],
"id": "GHSA-p6xc-xr62-6r2g",
"max_severity": "high",
"modified": "2026-06-09T10:30:14.432177927Z",
"published": "2021-12-18T18:00:07Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45105"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1541"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujan2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/930724"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2021/dsa-5024"
},
{
"type": "WEB",
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20211218-0001"
},
{
"type": "WEB",
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
},
{
"type": "WEB",
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/security.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00017.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/12/19/1"
}
],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion",
"withdrawn": false
},
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.logging.log4j:log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"events": [
{
"introduced": "2.0-beta9"
},
{
"fixed": "2.25.3"
}
],
"type": "ECOSYSTEM"
}
],
"severity": [],
"versions": [
"2.0",
"2.0-beta9",
"2.0-rc1",
"2.0-rc2",
"2.0.1",
"2.0.2",
"2.1",
"2.10.0",
"2.11.0",
"2.11.1",
"2.11.2",
"2.12.0",
"2.12.1",
"2.12.2",
"2.12.3",
"2.12.4",
"2.13.0",
"2.13.1",
"2.13.2",
"2.13.3",
"2.14.0",
"2.14.1",
"2.15.0",
"2.16.0",
"2.17.0",
"2.17.1",
"2.17.2",
"2.18.0",
"2.19.0",
"2.2",
"2.20.0",
"2.21.0",
"2.21.1",
"2.22.0",
"2.22.1",
"2.23.0",
"2.23.1",
"2.24.0",
"2.24.1",
"2.24.2",
"2.24.3",
"2.25.0",
"2.25.1",
"2.25.2",
"2.3",
"2.3.1",
"2.3.2",
"2.4",
"2.4.1",
"2.5",
"2.6",
"2.6.1",
"2.6.2",
"2.7",
"2.8",
"2.8.1",
"2.8.2",
"2.9.0",
"2.9.1"
]
}
],
"aliases": [
"CVE-2025-68161"
],
"fixed_versions": [
"2.25.3"
],
"id": "GHSA-vc5p-v9hr-52mj",
"max_severity": "medium",
"modified": "2026-02-04T03:10:00.616806Z",
"published": "2025-12-18T21:31:44Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68161"
},
{
"type": "WEB",
"url": "https://github.com/apache/logging-log4j2/pull/4002"
},
{
"type": "WEB",
"url": "https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578"
},
{
"type": "WEB",
"url": "https://github.com/apache/logging-log4j2"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx"
},
{
"type": "WEB",
"url": "https://logging.apache.org/cyclonedx/vdr.xml"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName"
},
{
"type": "WEB",
"url": "https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName"
},
{
"type": "WEB",
"url": "https://logging.apache.org/security.html#CVE-2025-68161"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/12/18/1"
}
],
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N",
"type": "CVSS_V4"
}
],
"summary": "Apache Log4j does not verify the TLS hostname in its Socket Appender",
"withdrawn": false
}
],
"input": {
"ecosystem": "maven",
"name": "org.apache.logging.log4j/log4j-core",
"purl": "pkg:maven/org.apache.logging.log4j/[email protected]",
"version": "2.14.1"
},
"operation": "package-check",
"retrieved_at": "2026-08-02T00:00:00Z",
"schema_version": "dependency-risk-v1",
"source": {
"cisa_kev": {
"catalog_version": "2026.07.29",
"date_released": "2026-07-29T18:45:59.5809Z",
"name": "Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog",
"retrieved_at": "2026-08-02T00:00:00Z"
},
"osv": {
"name": "OSV.dev"
}
},
"stale": false,
"status": "vulnerabilities_found",
"summary": {
"finding_count": 7,
"kev_count": 2,
"max_severity": "critical"
},
"warnings": []
},
"type": "json"
}
},
"schema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"purl": {
"description": "Canonical package URL containing an embedded exact version",
"maxLength": 2048,
"minLength": 1,
"type": "string"
}
},
"required": [
"purl"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"additionalProperties": false,
"description": "Complete transactional Dependency Risk response, limited to the native budget reserved below the 512 KiB deployed wire ceiling",
"properties": {
"_atlas": {
"additionalProperties": false,
"description": "Atlas documentation and related-route metadata added after deployment",
"properties": {
"docs": {
"description": "Documentation URL for this bridge",
"format": "uri",
"maxLength": 512,
"type": "string"
},
"related": {
"description": "Bounded related Atlas routes",
"items": {
"additionalProperties": false,
"description": "One related Atlas route",
"properties": {
"bridge": {
"description": "Related bridge name",
"maxLength": 64,
"type": "string"
},
"docs": {
"description": "Related bridge documentation URL",
"format": "uri",
"maxLength": 512,
"type": "string"
},
"summary": {
"description": "Short capability summary",
"maxLength": 256,
"type": "string"
},
"url": {
"description": "Related route URL",
"format": "uri",
"maxLength": 512,
"type": "string"
}
},
"required": [
"bridge",
"url",
"docs",
"summary"
],
"type": "object"
},
"maxItems": 3,
"type": "array"
}
},
"required": [
"docs"
],
"type": "object"
},
"findings": {
"description": "Complete normalized OSV findings sorted lexically by authoritative OSV ID; at most 16 from the one supported OSV page and always [] when none",
"items": {
"additionalProperties": false,
"description": "One complete normalized OSV vulnerability finding, limited to 48 KiB after JSON encoding, with optional exact CISA KEV enrichment",
"properties": {
"affected": {
"description": "Bounded OSV affected package/range/event data in source order",
"items": {
"additionalProperties": false,
"description": "One OSV affected package entry retained in source order",
"properties": {
"package": {
"additionalProperties": false,
"description": "Exact affected package identity published by OSV",
"properties": {
"ecosystem": {
"description": "Exact OSV ecosystem identifier",
"type": "string"
},
"name": {
"description": "Exact package name published by OSV",
"type": "string"
},
"purl": {
"description": "Package URL published by OSV when supplied",
"type": "string"
}
},
"type": "object"
},
"ranges": {
"description": "Affected ranges retained in OSV source order",
"items": {
"additionalProperties": false,
"description": "One affected version range published by OSV",
"properties": {
"events": {
"description": "Ordered OSV range events; the bridge does not infer ecosystem version ordering",
"items": {
"additionalProperties": false,
"description": "One OSV range event; exactly one event field is normally supplied by the source",
"properties": {
"fixed": {
"description": "OSV range event explicitly marking a fixed version",
"type": "string"
},
"introduced": {
"description": "OSV range event marking an introduced version",
"type": "string"
},
"last_affected": {
"description": "OSV range event marking the last affected version",
"type": "string"
},
"limit": {
"description": "OSV range event upper limit when supplied",
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"repo": {
"description": "Repository identifier published by OSV for a GIT range",
"type": "string"
},
"type": {
"description": "OSV range type such as SEMVER, ECOSYSTEM, or GIT",
"type": "string"
}
},
"required": [
"type",
"events"
],
"type": "object"
},
"type": "array"
},
"severity": {
"description": "Severity vectors attached to this affected package entry",
"items": {
"additionalProperties": false,
"description": "One severity vector exactly as published by OSV",
"properties": {
"score": {
"description": "Original published vector; malformed or mismatched vectors are retained but score as unknown",
"type": "string"
},
"type": {
"description": "OSV-declared score type such as CVSS_V3",
"type": "string"
}
},
"required": [
"type",
"score"
],
"type": "object"
},
"type": "array"
},
"versions": {
"description": "Affected versions explicitly enumerated by OSV",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"package",
"ranges",
"versions",
"severity"
],
"type": "object"
},
"type": "array"
},
"aliases": {
"description": "Deduplicated lexical aliases published by OSV",
"items": {
"type": "string"
},
"type": "array"
},
"fixed_versions": {
"description": "Only explicit fixed events for the matching package, deduplicated in OSV source order; [] means OSV supplied no fixed event, not that no fix exists",
"items": {
"type": "string"
},
"type": "array"
},
"id": {
"description": "Authoritative OSV record identifier",
"type": "string"
},
"kev": {
"additionalProperties": false,
"description": "Exact CISA KEV match on a syntactically valid CVE ID or alias; omitted rather than null when no exact match exists",
"properties": {
"cve_id": {
"description": "Exact CVE identifier matched in the CISA KEV catalog",
"type": "string"
},
"cwes": {
"description": "CWE identifiers published by CISA",
"items": {
"type": "string"
},
"type": "array"
},
"date_added": {
"description": "Date CISA added the CVE to KEV",
"type": "string"
},
"due_date": {
"description": "CISA KEV due date for covered federal agencies",
"type": "string"
},
"known_ransomware_campaign_use": {
"description": "CISA's published ransomware-campaign-use value when supplied",
"type": "string"
},
"notes": {
"description": "Additional CISA KEV notes when supplied",
"type": "string"
},
"product": {
"description": "Affected product label published by CISA",
"type": "string"
},
"required_action": {
"description": "Required action text published by CISA; caller remediation review is still required",
"type": "string"
},
"short_description": {
"description": "Short vulnerability description published by CISA",
"type": "string"
},
"vendor_project": {
"description": "Vendor or project label published by CISA",
"type": "string"
},
"vulnerability_name": {
"description": "CISA KEV vulnerability name",
"type": "string"
}
},
"required": [
"cve_id",
"vendor_project",
"product",
"vulnerability_name",
"date_added",
"short_description",
"required_action",
"due_date",
"cwes"
],
"type": "object"
},
"max_severity": {
"description": "Highest severity derived only from a parseable declared CVSS vector",
"enum": [
"unknown",
"low",
"medium",
"high",
"critical"
],
"type": "string"
},
"modified": {
"description": "OSV modification time string",
"type": "string"
},
"published": {
"description": "OSV publication time string when supplied",
"type": "string"
},
"references": {
"description": "Bounded references published by OSV; URLs are untrusted data returned for provenance and are never fetched by this bridge",
"items": {
"additionalProperties": false,
"description": "One OSV-published reference retained as provenance data",
"properties": {
"type": {
"description": "OSV reference classification such as ADVISORY, FIX, REPORT, or WEB",
"type": "string"
},
"url": {
"description": "Reference URL supplied by OSV as untrusted provenance data; never fetched by this bridge",
"type": "string"
}
},
"required": [
"type",
"url"
],
"type": "object"
},
"type": "array"
},
"severity": {
"description": "At most 16 published top-level OSV severity vectors",
"items": {
"additionalProperties": false,
"description": "One severity vector exactly as published by OSV",
"properties": {
"score": {
"description": "Original published vector; malformed or mismatched vectors are retained but score as unknown",
"type": "string"
},
"type": {
"description": "OSV-declared score type such as CVSS_V3",
"type": "string"
}
},
"required": [
"type",
"score"
],
"type": "object"
},
"maxItems": 16,
"type": "array"
},
"summary": {
"description": "Bounded OSV summary",
"type": "string"
},
"withdrawn": {
"description": "Whether OSV withdrew the record; withdrawn findings remain visible but do not count in the active summary",
"type": "boolean"
},
"withdrawn_at": {
"description": "OSV withdrawal time string, present only when supplied",
"type": "string"
}
},
"required": [
"id",
"aliases",
"modified",
"withdrawn",
"affected",
"references",
"severity",
"max_severity",
"fixed_versions"
],
"type": "object"
},
"maxItems": 16,
"type": "array"
},
"input": {
"additionalProperties": false,
"description": "Canonical exact package/version identity",
"properties": {
"ecosystem": {
"description": "Exact package ecosystem; purl types remain canonical lowercase identifiers",
"type": "string"
},
"name": {
"description": "Exact package-manager name",
"type": "string"
},
"purl": {
"description": "Canonical input purl when the caller used purl form; otherwise omitted",
"type": "string"
},
"version": {
"description": "Exact queried package version",
"type": "string"
}
},
"required": [
"ecosystem",
"name",
"version"
],
"type": "object"
},
"operation": {
"const": "package-check",
"description": "Stable route operation identifier",
"type": "string"
},
"retrieved_at": {
"description": "UTC time this bridge completed the response; this is not an OSV publication or modification time",
"format": "date-time",
"type": "string"
},
"schema_version": {
"const": "dependency-risk-v1",
"description": "Version of the normalized Dependency Risk response contract",
"type": "string"
},
"source": {
"additionalProperties": false,
"description": "Named public sources and the exact CISA KEV snapshot used for this response",
"properties": {
"cisa_kev": {
"additionalProperties": false,
"description": "Validated CISA Known Exploited Vulnerabilities snapshot used for exact CVE enrichment",
"properties": {
"catalog_version": {
"description": "Catalog version published in the validated CISA feed",
"type": "string"
},
"date_released": {
"description": "Release time published in the validated CISA feed",
"type": "string"
},
"name": {
"const": "Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog",
"description": "Official CISA KEV source name",
"type": "string"
},
"retrieved_at": {
"description": "UTC time this exact validated KEV snapshot was retrieved",
"format": "date-time",
"type": "string"
}
},
"required": [
"name",
"catalog_version",
"date_released",
"retrieved_at"
],
"type": "object"
},
"osv": {
"additionalProperties": false,
"description": "OSV source identity; individual finding times carry record publication and modification semantics",
"properties": {
"name": {
"const": "OSV.dev",
"description": "Official OSV.dev vulnerability record aggregator",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
}
},
"required": [
"osv",
"cisa_kev"
],
"type": "object"
},
"stale": {
"description": "True only when a prior validated CISA KEV snapshot is served after refresh failure; OSV result completeness is never silently marked stale",
"type": "boolean"
},
"status": {
"description": "Complete named-source result: no_known_vulnerabilities means OSV returned no matching active record, not that the dependency is safe",
"enum": [
"no_known_vulnerabilities",
"vulnerabilities_found"
],
"type": "string"
},
"summary": {
"additionalProperties": false,
"description": "Summary of active non-withdrawn findings",
"properties": {
"finding_count": {
"description": "Active non-withdrawn finding count",
"maximum": 16,
"minimum": 0,
"type": "integer"
},
"kev_count": {
"description": "Active findings with an exact KEV CVE match",
"maximum": 16,
"minimum": 0,
"type": "integer"
},
"max_severity": {
"description": "Highest parseable published CVSS severity among active findings",
"enum": [
"unknown",
"low",
"medium",
"high",
"critical"
],
"type": "string"
}
},
"required": [
"finding_count",
"kev_count",
"max_severity"
],
"type": "object"
},
"warnings": {
"description": "Freshness and interpretation warnings; always [] when none",
"items": {
"description": "Bounded warning intended for caller action or interpretation",
"type": "string"
},
"type": "array"
}
},
"required": [
"operation",
"schema_version",
"source",
"retrieved_at",
"stale",
"warnings",
"input",
"status",
"summary",
"findings"
],
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
},
"tags": [
"package-vulnerability-check",
"osv",
"cve",
"cisa-kev",
"software-supply-chain"
]
}
}Use it
curl
curl "https://dependency-risk.use.x402atlas.com/package" # -> 402 Payment Required, accepts[] lists how to pay # retry with a PAYMENT-SIGNATURE (or PAYMENT header) once paid
JavaScript
const res = await fetch("https://dependency-risk.use.x402atlas.com/package");
if (res.status === 402) {
const { accepts } = await res.json();
// pay one of accepts[] via an x402 client, then retry with the payment header
}Python
import httpx
res = httpx.get("https://dependency-risk.use.x402atlas.com/package")
if res.status_code == 402:
accepts = res.json()["accepts"]
# pay one of accepts[] via an x402 client, then retry with the payment headerMachine-readable
Everything on this page is also available as clean JSON at /resources/4489.json, and this resource appears in /discovery/resources and /discovery/search.