{"api":"v1","generated_at":"2026-09-16T01:58:15.888Z","licence":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/","attribution":"TOLL, with a link to the page cited"},"page":"https://tollindex.com/e/api-osf-master-server-com-x402-security-cve-cve-id-f478c8","pinned_page":"https://tollindex.com/e/api-osf-master-server-com-x402-security-cve-cve-id-f478c8/at/2026-09-15T21-20Z","pinned":false,"method":"https://tollindex.com/ledger/method","snapshot_at":"2026-09-15T21:20:12.737Z","snapshot_stamp":"2026-09-15T21-20Z","endpoint":{"slug":"api-osf-master-server-com-x402-security-cve-cve-id-f478c8","canonical_url":"https://api.osf-master-server.com/x402/security/cve/:cve_id","resource":"https://api.osf-master-server.com/x402/security/cve/:cve_id","http_method":"GET","type":"http","x402_version":2,"registries":["cdp"],"primary_registry":"cdp","curated_by_coinbase":false,"description":"CVE lookup and exploit check by CVE id. Answers is this CVE actively exploited in the wild using the US CISA Known Exploited Vulnerabilities (KEV) catalog, with the EPSS exploitation probability score and CVSS severity. Each field carries a provenance URL to the official US source. For vulnerability management, patch prioritization, threat intelligence, and DevSecOps agents.","service_name":"Open Source Filings","declared_category":null,"declared_tags":["cve","vulnerability","exploit","security","CVE lookup"],"route_template":"/x402/security/cve/:cve_id","registry_updated":"2026-08-26T06:17:30.322Z"},"derived":{"note":"fields no registry supplies; TOLL derives them and marks them derived on the page","title":"security cve","category":"inference","first_observed_by_toll":"2026-09-10T19:08:24.178Z","last_observed_by_toll":"2026-09-15T21:20:12.737Z","observation_began":"2026-09-10"},"presence":{"listed_now":true,"first_absent_at":null,"delisting_confirmed_at":null,"events":[{"registry":"cdp","at":"2026-09-10T19:08:24.178Z","event":"listed"}]},"accepts":[{"registry":"cdp","ordinal":0,"network":"eip155:8453","asset":"0x833589fcd6edb6e08f4c7c32d4f71b54bda02913","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.05 USDC","amount_units":0.05,"decimals_known":true,"pay_to":"0x72f62dE8b70d6CFa8Cc2dF6f21F243f289F3396c","scheme":"exact"}],"counters":{"observed_at":"2026-09-15T21:20:12.737Z","calls_30d":2,"unique_payers_30d":2,"last_called_at":"2026-08-26T06:17:30.092Z"},"validation":{"latest":{"observed_at":"2026-09-15T07:02:09.989Z","state":"fail","failed_checks":["endpoint_reachable"],"endpoint_http_status":null,"run_id":"daily-2026-09-15"},"uptime":[{"days":7,"observed":5,"passed":0,"ratio":0},{"days":30,"observed":5,"passed":0,"ratio":0},{"days":90,"observed":5,"passed":0,"ratio":0}],"history_90d":[{"observed_at":"2026-09-15T07:02:09.989Z","state":"fail","failed_checks":["endpoint_reachable"],"run_id":"daily-2026-09-15","state_changed":false},{"observed_at":"2026-09-14T06:28:47.268Z","state":"fail","failed_checks":["endpoint_reachable"],"run_id":"daily-2026-09-14","state_changed":false},{"observed_at":"2026-09-13T06:18:18.254Z","state":"fail","failed_checks":["endpoint_reachable"],"run_id":"daily-2026-09-13","state_changed":false},{"observed_at":"2026-09-12T09:38:21.534Z","state":"fail","failed_checks":["endpoint_reachable"],"run_id":"daily-2026-09-12","state_changed":false},{"observed_at":"2026-09-11T14:46:50.411Z","state":"fail","failed_checks":["endpoint_reachable"],"run_id":"daily-2026-09-11","state_changed":true}]},"seller":{"wallet":"0x72f62dE8b70d6CFa8Cc2dF6f21F243f289F3396c","page":"https://tollindex.com/seller/0x72f62dE8b70d6CFa8Cc2dF6f21F243f289F3396c","endpoints":18,"hosts":1},"reports":0,"registry_record":{"cdp":[{"tags":["cve","vulnerability","exploit","security","CVE lookup"],"type":"http","accepts":[{"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"name":"USD Coin","version":"2"},"payTo":"0x72f62dE8b70d6CFa8Cc2dF6f21F243f289F3396c","amount":"50000","scheme":"exact","network":"eip155:8453","maxTimeoutSeconds":300}],"quality":{"lastCalledAt":"2026-08-26T06:17:30.092Z","l30DaysTotalCalls":2,"l30DaysUniquePayers":2},"resource":"https://api.osf-master-server.com/x402/security/cve/:cve_id","extensions":{"bazaar":{"info":{"input":{"type":"http","method":"GET","pathParams":{"cve_id":":cve_id"},"queryParams":{"format":"json"}},"output":{"type":"json","example":{"nvd":{"cvss_severity":"CRITICAL"},"epss":{"epss_probability":0.984,"exploitation_band":"Critical"},"query":"CVE-2026-33017","result":"FOUND","service":"OSF Security - CVE Exploit Check","audit_receipt":{"check_id":"uuid","result_sha256":"..."},"coverage_note":"Direct lookup against the US CISA Known Exploited Vulnerabilities (KEV) catalog, the FIRST EPSS model score, and the NVD CVE record. 'actively_exploited' reflects presence on the CISA KEV catalog ONLY. A CVE that is NOT on KEV is not necessarily safe or unexploitable - it simply is not on CISA's confirmed-exploited list. EPSS is a probability estimate, not proof.","compliance_note":"This is a decision-support signal, not a guarantee. Confirm against the linked authoritative sources (cisa.gov, nvd.nist.gov, first.org) before acting.","provenance_urls":{"cisa_kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"},"actively_exploited":true,"exploitation_summary":"ON the CISA KEV catalog - confirmed exploited in the wild."}}},"schema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"pathParams":{"type":"object"},"queryParams":{"type":"object","required":["format"],"properties":{"format":{"type":"string","description":"Response format (json)."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["service","query","result","actively_exploited","compliance_note","audit_receipt"],"properties":{"nvd":{"type":"object"},"epss":{"type":"object"},"query":{"type":"string"},"result":{"type":"string","description":"FOUND, NOT_FOUND, or INVALID_INPUT"},"service":{"type":"string"},"audit_receipt":{"type":"object"},"coverage_note":{"type":"string"},"compliance_note":{"type":"string"},"provenance_urls":{"type":"object"},"actively_exploited":{"type":"boolean","description":"True if on the CISA KEV catalog."},"exploitation_summary":{"type":"string"}}}}}}},"routeTemplate":"/x402/security/cve/:cve_id"}},"description":"CVE lookup and exploit check by CVE id. Answers is this CVE actively exploited in the wild using the US CISA Known Exploited Vulnerabilities (KEV) catalog, with the EPSS exploitation probability score and CVSS severity. Each field carries a provenance URL to the official US source. For vulnerability management, patch prioritization, threat intelligence, and DevSecOps agents.","lastUpdated":"2026-08-26T06:17:30.322Z","serviceName":"Open Source Filings","x402Version":2}]}}