{"api":"v1","generated_at":"2026-09-15T23:48:56.298Z","licence":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/","attribution":"TOLL, with a link to the page cited"},"page":"https://tollindex.com/e/dependency-risk-use-x402atlas-com-package-bc6a3d","pinned_page":"https://tollindex.com/e/dependency-risk-use-x402atlas-com-package-bc6a3d/at/2026-09-15T21-20Z","pinned":false,"method":"https://tollindex.com/ledger/method","snapshot_at":"2026-09-15T21:20:12.737Z","snapshot_stamp":"2026-09-15T21-20Z","endpoint":{"slug":"dependency-risk-use-x402atlas-com-package-bc6a3d","canonical_url":"https://dependency-risk.use.x402atlas.com/package","resource":"https://dependency-risk.use.x402atlas.com/package","http_method":"POST","type":"http","x402_version":2,"registries":["cdp"],"primary_registry":"cdp","curated_by_coinbase":false,"description":"Package vulnerability check — check one exact open-source dependency version or purl against OSV, enrich CVE matches with CISA KEV known-exploited signals, and report fixes, severity, and provenance.","service_name":"Open Source Vulnerability Check","declared_category":"security","declared_tags":["package-vulnerability-check","osv","cve","cisa-kev","software-supply-chain"],"route_template":null,"registry_updated":"2026-09-15T06:32:24.934Z"},"derived":{"note":"fields no registry supplies; TOLL derives them and marks them derived on the page","title":"package","category":"market-data","first_observed_by_toll":"2026-09-10T19:08:24.178Z","last_observed_by_toll":"2026-09-15T21:20:12.737Z","observation_began":"2026-09-10"},"presence":{"listed_now":true,"first_absent_at":null,"delisting_confirmed_at":null,"events":[{"registry":"cdp","at":"2026-09-10T19:08:24.178Z","event":"listed"}]},"accepts":[{"registry":"cdp","ordinal":0,"network":"eip155:8453","asset":"0x833589fcd6edb6e08f4c7c32d4f71b54bda02913","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.005 USDC","amount_units":0.005,"decimals_known":true,"pay_to":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","scheme":"exact"},{"registry":"cdp","ordinal":1,"network":"eip155:137","asset":"0x3c499c542cef5e3811e1192ce70d8cc03d5c3359","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.005 USDC","amount_units":0.005,"decimals_known":true,"pay_to":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","scheme":"exact"},{"registry":"cdp","ordinal":2,"network":"eip155:42161","asset":"0xaf88d065e77c8cc2239327c5edb3a432268e5831","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.005 USDC","amount_units":0.005,"decimals_known":true,"pay_to":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","scheme":"exact"}],"counters":{"observed_at":"2026-09-15T21:20:12.737Z","calls_30d":2,"unique_payers_30d":1,"last_called_at":"2026-09-15T06:32:22.163Z"},"validation":{"latest":{"observed_at":"2026-09-15T06:22:43.773Z","state":"pass","failed_checks":[],"endpoint_http_status":402,"run_id":"daily-2026-09-15"},"uptime":[{"days":7,"observed":5,"passed":5,"ratio":1},{"days":30,"observed":5,"passed":5,"ratio":1},{"days":90,"observed":5,"passed":5,"ratio":1}],"history_90d":[{"observed_at":"2026-09-15T06:22:43.773Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-15","state_changed":false},{"observed_at":"2026-09-14T05:52:34.153Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-14","state_changed":false},{"observed_at":"2026-09-13T05:45:24.853Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-13","state_changed":false},{"observed_at":"2026-09-12T08:02:40.650Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-12","state_changed":false},{"observed_at":"2026-09-11T11:58:56.578Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-11","state_changed":true}]},"seller":{"wallet":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","page":"https://tollindex.com/seller/0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","endpoints":62,"hosts":18},"reports":0,"registry_record":{"cdp":[{"tags":["package-vulnerability-check","osv","cve","cisa-kev","software-supply-chain"],"type":"http","accepts":[{"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"name":"USD Coin","tier":"standard","version":"2","merchant":"x402Atlas"},"payTo":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","amount":"5000","scheme":"exact","network":"eip155:8453","maxTimeoutSeconds":300},{"asset":"0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359","extra":{"name":"USD Coin","tier":"standard","version":"2","merchant":"x402Atlas"},"payTo":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","amount":"5000","scheme":"exact","network":"eip155:137","maxTimeoutSeconds":300},{"asset":"0xaf88d065e77c8cC2239327C5EDb3A432268e5831","extra":{"name":"USD Coin","tier":"standard","version":"2","merchant":"x402Atlas"},"payTo":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","amount":"5000","scheme":"exact","network":"eip155:42161","maxTimeoutSeconds":300}],"quality":{"lastCalledAt":"2026-09-15T06:32:22.163Z","l30DaysTotalCalls":2,"l30DaysUniquePayers":1},"resource":"https://dependency-risk.use.x402atlas.com/package","extensions":{"bazaar":{"info":{"input":{"body":{"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1"},"type":"http","method":"POST","bodyType":"json"},"output":{"type":"json","example":{"input":{"name":"org.apache.logging.log4j/log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1","version":"2.14.1","ecosystem":"maven"},"stale":false,"source":{"osv":{"name":"OSV.dev"},"cisa_kev":{"name":"Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog","retrieved_at":"2026-08-02T00:00:00Z","date_released":"2026-07-29T18:45:59.5809Z","catalog_version":"2026.07.29"}},"status":"vulnerabilities_found","summary":{"kev_count":2,"max_severity":"critical","finding_count":7},"findings":[{"id":"GHSA-3pxv-7cmr-fjr4","aliases":["CVE-2026-34480"],"summary":"Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0-alpha1"},{"fixed":"2.25.4"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.0","2.0-alpha1","2.0-alpha2","2.0-beta1","2.0-beta2","2.0-beta3","2.0-beta4","2.0-beta5","2.0-beta6","2.0-beta7","2.0-beta8","2.0-beta9","2.0-rc1","2.0-rc2","2.0.1","2.0.2","2.1","2.10.0","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.17.1","2.17.2","2.18.0","2.19.0","2.2","2.20.0","2.21.0","2.21.1","2.22.0","2.22.1","2.23.0","2.23.1","2.24.0","2.24.1","2.24.2","2.24.3","2.25.0","2.25.1","2.25.2","2.25.3","2.3","2.3.1","2.3.2","2.4","2.4.1","2.5","2.6","2.6.1","2.6.2","2.7","2.8","2.8.1","2.8.2","2.9.0","2.9.1"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0-alpha1"},{"last_affected":"3.0.0-beta3"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["3.0.0-alpha1","3.0.0-beta1","3.0.0-beta2","3.0.0-beta3"]}],"modified":"2026-04-16T11:29:10.536806482Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}],"published":"2026-04-10T18:31:17Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34480","type":"ADVISORY"},{"url":"https://github.com/apache/logging-log4j2/pull/4077","type":"WEB"},{"url":"https://github.com/apache/logging-log4j2","type":"PACKAGE"},{"url":"https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","type":"WEB"},{"url":"https://logging.apache.org/cyclonedx/vdr.xml","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","type":"WEB"},{"url":"https://logging.apache.org/security.html#CVE-2026-34480","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2026/04/10/9","type":"WEB"}],"max_severity":"medium","fixed_versions":["2.25.4"]},{"id":"GHSA-6hg6-v5c8-fphq","aliases":["CVE-2026-34477"],"summary":"Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.12.0"},{"fixed":"2.25.4"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.17.1","2.17.2","2.18.0","2.19.0","2.20.0","2.21.0","2.21.1","2.22.0","2.22.1","2.23.0","2.23.1","2.24.0","2.24.1","2.24.2","2.24.3","2.25.0","2.25.1","2.25.2","2.25.3"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0-alpha1"},{"last_affected":"3.0.0-beta3"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["3.0.0-alpha1","3.0.0-beta1","3.0.0-beta2","3.0.0-beta3"]}],"modified":"2026-04-17T12:29:10.521430176Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N"}],"published":"2026-04-10T18:31:17Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34477","type":"ADVISORY"},{"url":"https://github.com/apache/logging-log4j2/pull/4075","type":"WEB"},{"url":"https://github.com/apache/logging-log4j2","type":"PACKAGE"},{"url":"https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","type":"WEB"},{"url":"https://logging.apache.org/cyclonedx/vdr.xml","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","type":"WEB"},{"url":"https://logging.apache.org/security.html#CVE-2026-34477","type":"WEB"}],"max_severity":"medium","fixed_versions":["2.25.4"]},{"id":"GHSA-7rjr-3q55-vv33","kev":{"cwes":["CWE-917"],"notes":"https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046","cve_id":"CVE-2021-45046","product":"Log4j2","due_date":"2023-05-22","date_added":"2023-05-01","vendor_project":"Apache","required_action":"Apply updates per vendor instructions.","short_description":"Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.","vulnerability_name":"Apache Log4j2 Deserialization of Untrusted Data Vulnerability","known_ransomware_campaign_use":"Known"},"aliases":["CVE-2021-45046"],"summary":"Incomplete fix for Apache Log4j vulnerability","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.13.0"},{"fixed":"2.16.0"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1","2.15.0"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.2"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.0","2.0-alpha1","2.0-alpha2","2.0-beta1","2.0-beta2","2.0-beta3","2.0-beta4","2.0-beta5","2.0-beta6","2.0-beta7","2.0-beta8","2.0-beta9","2.0-rc1","2.0-rc2","2.0.1","2.0.2","2.1","2.10.0","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.2","2.3","2.3.1","2.3.2","2.4","2.4.1","2.5","2.6","2.6.1","2.6.2","2.7","2.8","2.8.1","2.8.2","2.9.0","2.9.1"]}],"modified":"2025-10-22T19:37:53.742023Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H"}],"published":"2021-12-14T18:01:28Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-45046","type":"ADVISORY"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/alert-cve-2021-44228.html","type":"WEB"},{"url":"https://www.openwall.com/lists/oss-security/2021/12/14/4","type":"WEB"},{"url":"https://www.kb.cert.org/vuls/id/930724","type":"WEB"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html","type":"WEB"},{"url":"https://www.debian.org/security/2021/dsa-5022","type":"WEB"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-44228","type":"WEB"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046","type":"WEB"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","type":"WEB"},{"url":"https://security.gentoo.org/glsa/202310-16","type":"WEB"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","type":"WEB"},{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/security.html","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY","type":"WEB"},{"url":"https://github.com/advisories/GHSA-jfh8-c2jp-5v3q","type":"ADVISORY"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/14/4","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/15/3","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/18/1","type":"WEB"}],"max_severity":"critical","fixed_versions":["2.16.0","2.12.2"]},{"id":"GHSA-8489-44mv-ggj8","aliases":["CVE-2021-44832"],"summary":"Improper Input Validation and Injection in Apache Log4j2","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0-beta7"},{"fixed":"2.3.2"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.0","2.0-beta7","2.0-beta8","2.0-beta9","2.0-rc1","2.0-rc2","2.0.1","2.0.2","2.1","2.2","2.3","2.3.1"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4"},{"fixed":"2.12.4"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.10.0","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.12.2","2.12.3","2.4","2.4.1","2.5","2.6","2.6.1","2.6.2","2.7","2.8","2.8.1","2.8.2","2.9.0","2.9.1"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.13.0"},{"fixed":"2.17.1"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0"]}],"modified":"2026-06-09T10:45:14.253296471Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}],"published":"2022-01-04T16:14:20Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44832","type":"ADVISORY"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf","type":"WEB"},{"url":"https://github.com/apache/logging-log4j2","type":"PACKAGE"},{"url":"https://issues.apache.org/jira/browse/LOG4J2-3293","type":"WEB"},{"url":"https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143","type":"WEB"},{"url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC","type":"WEB"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","type":"WEB"},{"url":"https://security.netapp.com/advisory/ntap-20220104-0001","type":"WEB"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/28/1","type":"WEB"}],"max_severity":"medium","fixed_versions":["2.3.2","2.12.4","2.17.1"]},{"id":"GHSA-jfh8-c2jp-5v3q","kev":{"cwes":["CWE-20","CWE-400","CWE-502"],"notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-44228","cve_id":"CVE-2021-44228","product":"Log4j2","due_date":"2021-12-24","date_added":"2021-12-10","vendor_project":"Apache","required_action":"For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.","short_description":"Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.","vulnerability_name":"Apache Log4j2 Remote Code Execution Vulnerability","known_ransomware_campaign_use":"Known"},"aliases":["CVE-2021-44228"],"summary":"Remote code injection in Log4j","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.13.0"},{"fixed":"2.15.0"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0-beta9"},{"fixed":"2.3.1"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.0","2.0-beta9","2.0-rc1","2.0-rc2","2.0.1","2.0.2","2.1","2.2","2.3"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4"},{"fixed":"2.12.2"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.10.0","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.4","2.4.1","2.5","2.6","2.6.1","2.6.2","2.7","2.8","2.8.1","2.8.2","2.9.0","2.9.1"]}],"modified":"2025-10-22T19:37:02.616807Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H"}],"published":"2021-12-10T00:40:56Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44228","type":"ADVISORY"},{"url":"https://github.com/apache/logging-log4j2/pull/608","type":"WEB"},{"url":"https://github.com/github/advisory-database/pull/5501","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf","type":"WEB"},{"url":"https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html","type":"WEB"},{"url":"https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html","type":"WEB"},{"url":"https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html","type":"WEB"},{"url":"https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html","type":"WEB"},{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032","type":"WEB"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","type":"WEB"},{"url":"https://seclists.org/fulldisclosure/2022/Dec/2","type":"WEB"},{"url":"https://seclists.org/fulldisclosure/2022/Jul/11","type":"WEB"},{"url":"https://seclists.org/fulldisclosure/2022/Mar/23","type":"WEB"},{"url":"https://security.netapp.com/advisory/ntap-20211210-0007","type":"WEB"},{"url":"https://support.apple.com/kb/HT213189","type":"WEB"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","type":"WEB"},{"url":"https://twitter.com/kurtseifried/status/1469345530182455296","type":"WEB"},{"url":"https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001","type":"WEB"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228","type":"WEB"},{"url":"https://www.debian.org/security/2021/dsa-5020","type":"WEB"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html","type":"WEB"},{"url":"https://www.kb.cert.org/vuls/id/930724","type":"WEB"},{"url":"https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/alert-cve-2021-44228.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf","type":"WEB"},{"url":"https://github.com/advisories/GHSA-7rjr-3q55-vv33","type":"ADVISORY"},{"url":"https://github.com/apache/logging-log4j2","type":"PACKAGE"},{"url":"https://github.com/cisagov/log4j-affected-db","type":"WEB"},{"url":"https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md","type":"WEB"},{"url":"https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228","type":"WEB"},{"url":"https://github.com/tangxiaofeng7/apache-log4j-poc","type":"WEB"},{"url":"https://issues.apache.org/jira/browse/LOG4J2-3198","type":"WEB"},{"url":"https://issues.apache.org/jira/browse/LOG4J2-3201","type":"WEB"},{"url":"https://issues.apache.org/jira/browse/LOG4J2-3214","type":"WEB"},{"url":"https://issues.apache.org/jira/browse/LOG4J2-3221","type":"WEB"},{"url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/changes-report.html#a2.15.0","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/manual/lookups.html#JndiLookup","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/manual/migration.html","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/security.html","type":"WEB"},{"url":"https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html","type":"WEB"},{"url":"http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html","type":"WEB"},{"url":"http://seclists.org/fulldisclosure/2022/Dec/2","type":"WEB"},{"url":"http://seclists.org/fulldisclosure/2022/Jul/11","type":"WEB"},{"url":"http://seclists.org/fulldisclosure/2022/Mar/23","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/10/1","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/10/2","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/10/3","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/13/1","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/13/2","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/14/4","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/15/3","type":"WEB"}],"max_severity":"critical","fixed_versions":["2.15.0","2.3.1","2.12.2"]},{"id":"GHSA-p6xc-xr62-6r2g","aliases":["CVE-2021-45105"],"summary":"Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.0"},{"fixed":"2.12.3"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.10.0","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.12.2","2.4","2.4.1","2.5","2.6","2.6.1","2.6.2","2.7","2.8","2.8.1","2.8.2","2.9.0","2.9.1"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.13.0"},{"fixed":"2.17.0"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1","2.15.0","2.16.0"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.1"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.0","2.0-alpha1","2.0-alpha2","2.0-beta1","2.0-beta2","2.0-beta3","2.0-beta4","2.0-beta5","2.0-beta6","2.0-beta7","2.0-beta8","2.0-beta9","2.0-rc1","2.0-rc2","2.0.1","2.0.2","2.1","2.2","2.3"]}],"modified":"2026-06-09T10:30:14.432177927Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"}],"published":"2021-12-18T18:00:07Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-45105","type":"ADVISORY"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-21-1541","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","type":"WEB"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","type":"WEB"},{"url":"https://www.kb.cert.org/vuls/id/930724","type":"WEB"},{"url":"https://www.debian.org/security/2021/dsa-5024","type":"WEB"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","type":"WEB"},{"url":"https://security.netapp.com/advisory/ntap-20211218-0001","type":"WEB"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","type":"WEB"},{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/security.html","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ","type":"WEB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY","type":"WEB"},{"url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00017.html","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf","type":"WEB"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/19/1","type":"WEB"}],"max_severity":"high","fixed_versions":["2.12.3","2.17.0","2.3.1"]},{"id":"GHSA-vc5p-v9hr-52mj","aliases":["CVE-2025-68161"],"summary":"Apache Log4j does not verify the TLS hostname in its Socket Appender","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0-beta9"},{"fixed":"2.25.3"}]}],"package":{"name":"org.apache.logging.log4j:log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core","ecosystem":"Maven"},"severity":[],"versions":["2.0","2.0-beta9","2.0-rc1","2.0-rc2","2.0.1","2.0.2","2.1","2.10.0","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.17.1","2.17.2","2.18.0","2.19.0","2.2","2.20.0","2.21.0","2.21.1","2.22.0","2.22.1","2.23.0","2.23.1","2.24.0","2.24.1","2.24.2","2.24.3","2.25.0","2.25.1","2.25.2","2.3","2.3.1","2.3.2","2.4","2.4.1","2.5","2.6","2.6.1","2.6.2","2.7","2.8","2.8.1","2.8.2","2.9.0","2.9.1"]}],"modified":"2026-02-04T03:10:00.616806Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N"}],"published":"2025-12-18T21:31:44Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68161","type":"ADVISORY"},{"url":"https://github.com/apache/logging-log4j2/pull/4002","type":"WEB"},{"url":"https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578","type":"WEB"},{"url":"https://github.com/apache/logging-log4j2","type":"WEB"},{"url":"https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx","type":"WEB"},{"url":"https://logging.apache.org/cyclonedx/vdr.xml","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","type":"WEB"},{"url":"https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName","type":"WEB"},{"url":"https://logging.apache.org/security.html#CVE-2025-68161","type":"WEB"},{"url":"http://www.openwall.com/lists/oss-security/2025/12/18/1","type":"WEB"}],"max_severity":"medium","fixed_versions":["2.25.3"]}],"warnings":[],"operation":"package-check","retrieved_at":"2026-08-02T00:00:00Z","schema_version":"dependency-risk-v1"}}},"tags":["package-vulnerability-check","osv","cve","cisa-kev","software-supply-chain"],"schema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"type":"object","required":["purl"],"properties":{"purl":{"type":"string","maxLength":2048,"minLength":1,"description":"Canonical package URL containing an embedded exact version"}},"additionalProperties":false},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["operation","schema_version","source","retrieved_at","stale","warnings","input","status","summary","findings"],"properties":{"input":{"type":"object","required":["ecosystem","name","version"],"properties":{"name":{"type":"string","description":"Exact package-manager name"},"purl":{"type":"string","description":"Canonical input purl when the caller used purl form; otherwise omitted"},"version":{"type":"string","description":"Exact queried package version"},"ecosystem":{"type":"string","description":"Exact package ecosystem; purl types remain canonical lowercase identifiers"}},"description":"Canonical exact package/version identity","additionalProperties":false},"stale":{"type":"boolean","description":"True only when a prior validated CISA KEV snapshot is served after refresh failure; OSV result completeness is never silently marked stale"},"_atlas":{"type":"object","required":["docs"],"properties":{"docs":{"type":"string","format":"uri","maxLength":512,"description":"Documentation URL for this bridge"},"related":{"type":"array","items":{"type":"object","required":["bridge","url","docs","summary"],"properties":{"url":{"type":"string","format":"uri","maxLength":512,"description":"Related route URL"},"docs":{"type":"string","format":"uri","maxLength":512,"description":"Related bridge documentation URL"},"bridge":{"type":"string","maxLength":64,"description":"Related bridge name"},"summary":{"type":"string","maxLength":256,"description":"Short capability summary"}},"description":"One related Atlas route","additionalProperties":false},"maxItems":3,"description":"Bounded related Atlas routes"}},"description":"Atlas documentation and related-route metadata added after deployment","additionalProperties":false},"source":{"type":"object","required":["osv","cisa_kev"],"properties":{"osv":{"type":"object","required":["name"],"properties":{"name":{"type":"string","const":"OSV.dev","description":"Official OSV.dev vulnerability record aggregator"}},"description":"OSV source identity; individual finding times carry record publication and modification semantics","additionalProperties":false},"cisa_kev":{"type":"object","required":["name","catalog_version","date_released","retrieved_at"],"properties":{"name":{"type":"string","const":"Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog","description":"Official CISA KEV source name"},"retrieved_at":{"type":"string","format":"date-time","description":"UTC time this exact validated KEV snapshot was retrieved"},"date_released":{"type":"string","description":"Release time published in the validated CISA feed"},"catalog_version":{"type":"string","description":"Catalog version published in the validated CISA feed"}},"description":"Validated CISA Known Exploited Vulnerabilities snapshot used for exact CVE enrichment","additionalProperties":false}},"description":"Named public sources and the exact CISA KEV snapshot used for this response","additionalProperties":false},"status":{"enum":["no_known_vulnerabilities","vulnerabilities_found"],"type":"string","description":"Complete named-source result: no_known_vulnerabilities means OSV returned no matching active record, not that the dependency is safe"},"summary":{"type":"object","required":["finding_count","kev_count","max_severity"],"properties":{"kev_count":{"type":"integer","maximum":16,"minimum":0,"description":"Active findings with an exact KEV CVE match"},"max_severity":{"enum":["unknown","low","medium","high","critical"],"type":"string","description":"Highest parseable published CVSS severity among active findings"},"finding_count":{"type":"integer","maximum":16,"minimum":0,"description":"Active non-withdrawn finding count"}},"description":"Summary of active non-withdrawn findings","additionalProperties":false},"findings":{"type":"array","items":{"type":"object","required":["id","aliases","modified","withdrawn","affected","references","severity","max_severity","fixed_versions"],"properties":{"id":{"type":"string","description":"Authoritative OSV record identifier"},"kev":{"type":"object","required":["cve_id","vendor_project","product","vulnerability_name","date_added","short_description","required_action","due_date","cwes"],"properties":{"cwes":{"type":"array","items":{"type":"string"},"description":"CWE identifiers published by CISA"},"notes":{"type":"string","description":"Additional CISA KEV notes when supplied"},"cve_id":{"type":"string","description":"Exact CVE identifier matched in the CISA KEV catalog"},"product":{"type":"string","description":"Affected product label published by CISA"},"due_date":{"type":"string","description":"CISA KEV due date for covered federal agencies"},"date_added":{"type":"string","description":"Date CISA added the CVE to KEV"},"vendor_project":{"type":"string","description":"Vendor or project label published by CISA"},"required_action":{"type":"string","description":"Required action text published by CISA; caller remediation review is still required"},"short_description":{"type":"string","description":"Short vulnerability description published by CISA"},"vulnerability_name":{"type":"string","description":"CISA KEV vulnerability name"},"known_ransomware_campaign_use":{"type":"string","description":"CISA's published ransomware-campaign-use value when supplied"}},"description":"Exact CISA KEV match on a syntactically valid CVE ID or alias; omitted rather than null when no exact match exists","additionalProperties":false},"aliases":{"type":"array","items":{"type":"string"},"description":"Deduplicated lexical aliases published by OSV"},"summary":{"type":"string","description":"Bounded OSV summary"},"affected":{"type":"array","items":{"type":"object","required":["package","ranges","versions","severity"],"properties":{"ranges":{"type":"array","items":{"type":"object","required":["type","events"],"properties":{"repo":{"type":"string","description":"Repository identifier published by OSV for a GIT range"},"type":{"type":"string","description":"OSV range type such as SEMVER, ECOSYSTEM, or GIT"},"events":{"type":"array","items":{"type":"object","properties":{"fixed":{"type":"string","description":"OSV range event explicitly marking a fixed version"},"limit":{"type":"string","description":"OSV range event upper limit when supplied"},"introduced":{"type":"string","description":"OSV range event marking an introduced version"},"last_affected":{"type":"string","description":"OSV range event marking the last affected version"}},"description":"One OSV range event; exactly one event field is normally supplied by the source","additionalProperties":false},"description":"Ordered OSV range events; the bridge does not infer ecosystem version ordering"}},"description":"One affected version range published by OSV","additionalProperties":false},"description":"Affected ranges retained in OSV source order"},"package":{"type":"object","properties":{"name":{"type":"string","description":"Exact package name published by OSV"},"purl":{"type":"string","description":"Package URL published by OSV when supplied"},"ecosystem":{"type":"string","description":"Exact OSV ecosystem identifier"}},"description":"Exact affected package identity published by OSV","additionalProperties":false},"severity":{"type":"array","items":{"type":"object","required":["type","score"],"properties":{"type":{"type":"string","description":"OSV-declared score type such as CVSS_V3"},"score":{"type":"string","description":"Original published vector; malformed or mismatched vectors are retained but score as unknown"}},"description":"One severity vector exactly as published by OSV","additionalProperties":false},"description":"Severity vectors attached to this affected package entry"},"versions":{"type":"array","items":{"type":"string"},"description":"Affected versions explicitly enumerated by OSV"}},"description":"One OSV affected package entry retained in source order","additionalProperties":false},"description":"Bounded OSV affected package/range/event data in source order"},"modified":{"type":"string","description":"OSV modification time string"},"severity":{"type":"array","items":{"type":"object","required":["type","score"],"properties":{"type":{"type":"string","description":"OSV-declared score type such as CVSS_V3"},"score":{"type":"string","description":"Original published vector; malformed or mismatched vectors are retained but score as unknown"}},"description":"One severity vector exactly as published by OSV","additionalProperties":false},"maxItems":16,"description":"At most 16 published top-level OSV severity vectors"},"published":{"type":"string","description":"OSV publication time string when supplied"},"withdrawn":{"type":"boolean","description":"Whether OSV withdrew the record; withdrawn findings remain visible but do not count in the active summary"},"references":{"type":"array","items":{"type":"object","required":["type","url"],"properties":{"url":{"type":"string","description":"Reference URL supplied by OSV as untrusted provenance data; never fetched by this bridge"},"type":{"type":"string","description":"OSV reference classification such as ADVISORY, FIX, REPORT, or WEB"}},"description":"One OSV-published reference retained as provenance data","additionalProperties":false},"description":"Bounded references published by OSV; URLs are untrusted data returned for provenance and are never fetched by this bridge"},"max_severity":{"enum":["unknown","low","medium","high","critical"],"type":"string","description":"Highest severity derived only from a parseable declared CVSS vector"},"withdrawn_at":{"type":"string","description":"OSV withdrawal time string, present only when supplied"},"fixed_versions":{"type":"array","items":{"type":"string"},"description":"Only explicit fixed events for the matching package, deduplicated in OSV source order; [] means OSV supplied no fixed event, not that no fix exists"}},"description":"One complete normalized OSV vulnerability finding, limited to 48 KiB after JSON encoding, with optional exact CISA KEV enrichment","additionalProperties":false},"maxItems":16,"description":"Complete normalized OSV findings sorted lexically by authoritative OSV ID; at most 16 from the one supported OSV page and always [] when none"},"warnings":{"type":"array","items":{"type":"string","description":"Bounded warning intended for caller action or interpretation"},"description":"Freshness and interpretation warnings; always [] when none"},"operation":{"type":"string","const":"package-check","description":"Stable route operation identifier"},"retrieved_at":{"type":"string","format":"date-time","description":"UTC time this bridge completed the response; this is not an OSV publication or modification time"},"schema_version":{"type":"string","const":"dependency-risk-v1","description":"Version of the normalized Dependency Risk response contract"}},"description":"Complete transactional Dependency Risk response, limited to the native budget reserved below the 512 KiB deployed wire ceiling","additionalProperties":false}}}}},"category":"security"}},"description":"Package vulnerability check — check one exact open-source dependency version or purl against OSV, enrich CVE matches with CISA KEV known-exploited signals, and report fixes, severity, and provenance.","lastUpdated":"2026-09-15T06:32:24.934Z","serviceName":"Open Source Vulnerability Check","x402Version":2}]}}