faillisted in Coinbase#3 by calls of 14 on this host
0.05 USDC
per call, as the listing declares it on eip155:
- Validation state
- fail
- Uptime, 7 / 30 / 90 days
- 0% / 0% / 0%
- Calls, trailing 30 days
- 2
- Unique payers, trailing 30 days
- 2
- Last called
- 2026-08-26 06:17 UTC
- First observed by TOLLderived
- 2026-09-10
- Pricederived
- 0.05 USDC
- Networks
- 1
How big is this endpoint among the ones like it?
No trace is drawn of this endpoint’s own volume. Its counters have changed 1 time across 29 observations, and 3 changes are the fewest this site will draw a trace through, because two points and a guess are not a series. Every observation is in the JSON.
The sweep of 2026-09-15 found security cve unreachable.
security cve, a GET endpoint on api.osf-master-server.com, appears in the Coinbase registry; TOLL's taxonomy puts it in inference.
On Base, security cve asks 0.05 USDC per call.
Callers of security cve supply the query parameter format and the path parameter cve_id.
A response from security cve, as declared, includes nvd, epss, query, result, service, audit_receipt and 2 others.
security cve drew 2 calls from 2 unique payers in the trailing 30 days, every call from a different payer.
security cve was last called 21 days before the snapshot.
With 14 endpoints listed on api.osf-master-server.com, security cve is tied 3rd by calls with 1 other.
6% of the host's counted calls go to it.
security cve is priced above 71% of comparable listings in inference.
Closest in price to security cve within inference: check site at x402.cloudpulsepoint.com and github repo analyze at api.strale.io.
The wallet paid by security cve is the payee of 18 endpoints on one host.
Seller tags: cve, vulnerability, exploit and security.
The price of security cve is declared by 100 other listings in inference too.
the payment options, as of 2026-09-15 21:20 UTC · method · pinnable
| registry | network | asset | amount | scheme | pay to |
|---|---|---|---|---|---|
| Coinbase | eip155: | USDC | 0.05 USDC | exact | 0x72f62d…F3396c |
the checks, as of 2026-09-15 07:02 UTC · method · pinnableendpoint answered HTTP none
endpoint_reachable· the endpoint answered at all
Every sweep that observed this endpoint, newest first.
| observed, UTC | state | failed checks | sweep |
|---|---|---|---|
| 2026-09-15 07:02 UTC | fail | 1 | daily-2026-09-15 |
| 2026-09-14 06:28 UTC | fail | 1 | daily-2026-09-14 |
| 2026-09-13 06:18 UTC | fail | 1 | daily-2026-09-13 |
| 2026-09-12 09:38 UTC | fail | 1 | daily-2026-09-12 |
| 2026-09-11 14:46 UTC | fail | 1 | daily-2026-09-11 |
Presence in a registry, not liveness of the service (method). Newest first.
- listed in Coinbase
From the registry record, not validated by TOLL.the declared schema, as of 2026-08-26 06:17 UTC · method · live
The input and output block
{
"input": {
"type": "http",
"method": "GET",
"pathParams": {
"cve_id": ":cve_id"
},
"queryParams": {
"format": "json"
}
},
"output": {
"type": "json",
"example": {
"nvd": {
"cvss_severity": "CRITICAL"
},
"epss": {
"epss_probability": 0.984,
"exploitation_band": "Critical"
},
"query": "CVE-2026-33017",
"result": "FOUND",
"service": "OSF Security - CVE Exploit Check",
"audit_receipt": {
"check_id": "uuid",
"result_sha256": "..."
},
"coverage_note": "Direct lookup against the US CISA Known Exploited Vulnerabilities (KEV) catalog, the FIRST EPSS model score, and the NVD CVE record. 'actively_exploited' reflects presence on the CISA KEV catalog ONLY. A CVE that is NOT on KEV is not necessarily safe or unexploitable - it simply is not on CISA's confirmed-exploited list. EPSS is a probability estimate, not proof.",
"compliance_note": "This is a decision-support signal, not a guarantee. Confirm against the linked authoritative sources (cisa.gov, nvd.nist.gov, first.org) before acting.",
"provenance_urls": {
"cisa_kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
},
"actively_exploited": true,
"exploitation_summary": "ON the CISA KEV catalog - confirmed exploited in the wild."
}
}
}Cite this page
The pinned URL below renders this page from the snapshot of 2026-09-15 21:20 UTC and does not change; the live page does, every six hours. Data reuse is under CC BY 4.0 (terms).
Plain text
TOLL, "security cve on api.osf-master-server.com", snapshot of 2026-09-15 21:20 UTC. https://tollindex.com/e/api-osf-master-server-com-x402-security-cve-cve-id-f478c8/at/2026-09-15T21-20Z. Accessed [access date].
BibTeX
@misc{toll-e-api-osf-master-server-com-x402-security-cve-cve-id-f478c8-2026-09-15T21-20Z,
author = {TOLL},
title = {security cve on api.osf-master-server.com},
howpublished = {\url{https://tollindex.com/e/api-osf-master-server-com-x402-security-cve-cve-id-f478c8/at/2026-09-15T21-20Z}},
year = {2026},
month = {9},
note = {Pinned view of the snapshot of 2026-09-15 21:20 UTC. Accessed [access date].}
}None yet. Anything submitted through the form below is published here with its outcome.