TOLL

What software pays for, recorded every six hours.

Snapshot
2026-09-15 21:20 UTC
Sweep
daily-2026-09-15 · finished 2026-09-15 07:10 UTC
Listed
16,178

sbom derived

dependency-risk.use.x402atlas.comMarket dataderived

POST https://dependency-risk.use.x402atlas.com/sbom

passlisted in Coinbase#2 by calls of 3 on this host

0.02 USDC

per call, as the listing declares it on eip155:8453

Compare with anotherEvery figure as JSONCite this page

the price, as of 2026-09-15 21:20 UTC · method · pinnable

Validation state
pass
as of 2026-09-15 06:37 UTC · method · pinnable · sweep daily-2026-09-15
Uptime, 7 / 30 / 90 days
100% / 100% / 100%
as of 2026-09-15 06:37 UTC · method · pinnable · 5 of 5 in 7d, 5 of 5 in 30d, 5 of 5 in 90d
Calls, trailing 30 days
2
as of 2026-09-15 21:20 UTC · method · pinnable
Unique payers, trailing 30 days
1
as of 2026-09-15 21:20 UTC · method · pinnable
Last called
2026-09-15 06:32 UTC
as of 2026-09-15 21:20 UTC · method · pinnable
First observed by TOLLderived
2026-09-10
as of 2026-09-10 19:08 UTC · method · pinnable · observation began 10 September 2026; listings that predate it show that date
Pricederived
0.02 USDC
as of 2026-09-15 21:20 UTC · method · pinnable · on eip155:8453
Networks
3
as of 2026-09-15 21:20 UTC · method · pinnable

Counters

29 observations, 2 of them a change, fewer than the 3 a trace needs

How big is this endpoint among the ones like it?

1 call100,000this endpoint
Calls counted in the trailing thirty days across the 5,288 endpoints in Market data that carry counters, binned on a logarithmic scale because the range runs over five orders of magnitude. The marked bin is this endpoint, at 2: 2,121 in the category are counted higher and 3,166 lower.

No trace is drawn of this endpoint’s own volume. Its counters have changed 2 times across 29 observations, and 3 changes are the fewest this site will draw a trace through, because two points and a guess are not a series. Every observation is in the JSON.

In words

dependency-risk.use.x402atlas.com serves sbom, a POST endpoint that TOLL places in market data, listed in the Coinbase registry.

A call to sbom costs 0.02 USDC on Base, as declared.

sbom takes a json body with the field document.

For sbom the listing declares 3 accepts on Base, Polygon and Arbitrum, all to one wallet.

sbom returns json; the example shows stale, source, partial, results, warnings, operation and 2 others.

sbom answered the sweep of 2026-09-15 with a valid 402, as at every sweep since 2026-09-11.

sbom is one of 3 listed endpoints on dependency-risk.use.x402atlas.com, tied 2nd by calls with 1 other among them.

sbom takes 29% of the calls counted across dependency-risk.use.x402atlas.com.

Over 30 days: 2 calls, one payer.

sbom was last called 1 day before the snapshot.

Closest in price to sbom within market data: liquidations btc at kronossignals.com and analyze at svm402.com.

Among comparable prices in market data, sbom sits above 64% of them.

Its payee wallet receives for 62 listed endpoints across 18 hosts.

The seller's tags on sbom are cyclonedx-sbom-check, osv, cve and cisa-kev, and its label is "security".

The price of sbom is declared by 471 other listings in market data too.

Payment options as declared

the payment options, as of 2026-09-15 21:20 UTC · method · pinnable

Every payment option declared on this listing
registrynetworkassetamountschemepay to
Coinbaseeip155:8453USDC0.02 USDCexact0x8C128f…5Df1b2
Coinbaseeip155:137USDC0.02 USDCexact0x8C128f…5Df1b2
Coinbaseeip155:42161USDC0.02 USDCexact0x8C128f…5Df1b2

Preflight checks at the last sweep

the checks, as of 2026-09-15 06:37 UTC · method · pinnableendpoint answered HTTP 402

No named check failed.

Validation history, 90 days

Every sweep that observed this endpoint, newest first.

Validation observations over the last 90 days
observed, UTCstatefailed checkssweep
2026-09-15 06:37 UTCpass0daily-2026-09-15
2026-09-14 06:06 UTCpass0daily-2026-09-14
2026-09-13 05:57 UTCpass0daily-2026-09-13
2026-09-12 08:15 UTCpass0daily-2026-09-12
2026-09-11 12:42 UTCpass0daily-2026-09-11

Registry presence

Presence in a registry, not liveness of the service (method). Newest first.

  1. listed in Coinbase

Declared input and output, as listed

From the registry record, not validated by TOLL.the declared schema, as of 2026-09-15 06:32 UTC · method · live

The input and output block
{
  "input": {
    "body": {
      "document": {
        "bomFormat": "CycloneDX",
        "components": [
          {
            "name": "log4j-core",
            "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1",
            "type": "library",
            "version": "2.14.1"
          }
        ],
        "specVersion": "1.5"
      }
    },
    "type": "http",
    "method": "POST",
    "bodyType": "json"
  },
  "output": {
    "type": "json",
    "example": {
      "stale": false,
      "source": {
        "osv": {
          "name": "OSV.dev"
        },
        "cisa_kev": {
          "name": "Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog",
          "retrieved_at": "2026-08-02T00:00:00Z",
          "date_released": "2026-07-29T18:45:59.5809Z",
          "catalog_version": "2026.07.29"
        }
      },
      "partial": false,
      "results": [
        {
          "input": {
            "name": "org.apache.logging.log4j/log4j-core",
            "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1",
            "version": "2.14.1",
            "ecosystem": "maven"
          },
          "status": "vulnerabilities_found",
          "summary": {
            "kev_count": 2,
            "max_severity": "critical",
            "finding_count": 7
          },
          "findings": [
            {
              "id": "GHSA-3pxv-7cmr-fjr4",
              "aliases": [
                "CVE-2026-34480"
              ],
              "summary": "Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.0-alpha1"
                        },
                        {
                          "fixed": "2.25.4"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-alpha1",
                    "2.0-alpha2",
                    "2.0-beta1",
                    "2.0-beta2",
                    "2.0-beta3",
                    "2.0-beta4",
                    "2.0-beta5",
                    "2.0-beta6",
                    "2.0-beta7",
                    "2.0-beta8",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.12.3",
                    "2.12.4",
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0",
                    "2.17.0",
                    "2.17.1",
                    "2.17.2",
                    "2.18.0",
                    "2.19.0",
                    "2.2",
                    "2.20.0",
                    "2.21.0",
                    "2.21.1",
                    "2.22.0",
                    "2.22.1",
                    "2.23.0",
                    "2.23.1",
                    "2.24.0",
                    "2.24.1",
                    "2.24.2",
                    "2.24.3",
                    "2.25.0",
                    "2.25.1",
                    "2.25.2",
                    "2.25.3",
                    "2.3",
                    "2.3.1",
                    "2.3.2",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "3.0.0-alpha1"
                        },
                        {
                          "last_affected": "3.0.0-beta3"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "3.0.0-alpha1",
                    "3.0.0-beta1",
                    "3.0.0-beta2",
                    "3.0.0-beta3"
                  ]
                }
              ],
              "modified": "2026-04-16T11:29:10.536806482Z",
              "severity": [
                {
                  "type": "CVSS_V4",
                  "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
                }
              ],
              "published": "2026-04-10T18:31:17Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34480",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/pull/4077",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "PACKAGE"
                },
                {
                  "url": "https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/cyclonedx/vdr.xml",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/security.html#CVE-2026-34480",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2026/04/10/9",
                  "type": "WEB"
                }
              ],
              "max_severity": "medium",
              "fixed_versions": [
                "2.25.4"
              ]
            },
            {
              "id": "GHSA-6hg6-v5c8-fphq",
              "aliases": [
                "CVE-2026-34477"
              ],
              "summary": "Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.12.0"
                        },
                        {
                          "fixed": "2.25.4"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.12.3",
                    "2.12.4",
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0",
                    "2.17.0",
                    "2.17.1",
                    "2.17.2",
                    "2.18.0",
                    "2.19.0",
                    "2.20.0",
                    "2.21.0",
                    "2.21.1",
                    "2.22.0",
                    "2.22.1",
                    "2.23.0",
                    "2.23.1",
                    "2.24.0",
                    "2.24.1",
                    "2.24.2",
                    "2.24.3",
                    "2.25.0",
                    "2.25.1",
                    "2.25.2",
                    "2.25.3"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "3.0.0-alpha1"
                        },
                        {
                          "last_affected": "3.0.0-beta3"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "3.0.0-alpha1",
                    "3.0.0-beta1",
                    "3.0.0-beta2",
                    "3.0.0-beta3"
                  ]
                }
              ],
              "modified": "2026-04-17T12:29:10.521430176Z",
              "severity": [
                {
                  "type": "CVSS_V4",
                  "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N"
                }
              ],
              "published": "2026-04-10T18:31:17Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34477",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/pull/4075",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "PACKAGE"
                },
                {
                  "url": "https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/cyclonedx/vdr.xml",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/security.html#CVE-2026-34477",
                  "type": "WEB"
                }
              ],
              "max_severity": "medium",
              "fixed_versions": [
                "2.25.4"
              ]
            },
            {
              "id": "GHSA-7rjr-3q55-vv33",
              "kev": {
                "cwes": [
                  "CWE-917"
                ],
                "notes": "https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046",
                "cve_id": "CVE-2021-45046",
                "product": "Log4j2",
                "due_date": "2023-05-22",
                "date_added": "2023-05-01",
                "vendor_project": "Apache",
                "required_action": "Apply updates per vendor instructions.",
                "short_description": "Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.",
                "vulnerability_name": "Apache Log4j2 Deserialization of Untrusted Data Vulnerability",
                "known_ransomware_campaign_use": "Known"
              },
              "aliases": [
                "CVE-2021-45046"
              ],
              "summary": "Incomplete fix for Apache Log4j vulnerability",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.13.0"
                        },
                        {
                          "fixed": "2.16.0"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "0"
                        },
                        {
                          "fixed": "2.12.2"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-alpha1",
                    "2.0-alpha2",
                    "2.0-beta1",
                    "2.0-beta2",
                    "2.0-beta3",
                    "2.0-beta4",
                    "2.0-beta5",
                    "2.0-beta6",
                    "2.0-beta7",
                    "2.0-beta8",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.2",
                    "2.3",
                    "2.3.1",
                    "2.3.2",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                }
              ],
              "modified": "2025-10-22T19:37:53.742023Z",
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H"
                }
              ],
              "published": "2021-12-14T18:01:28Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45046",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujul2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.openwall.com/lists/oss-security/2021/12/14/4",
                  "type": "WEB"
                },
                {
                  "url": "https://www.kb.cert.org/vuls/id/930724",
                  "type": "WEB"
                },
                {
                  "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.debian.org/security/2021/dsa-5022",
                  "type": "WEB"
                },
                {
                  "url": "https://www.cve.org/CVERecord?id=CVE-2021-44228",
                  "type": "WEB"
                },
                {
                  "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046",
                  "type": "WEB"
                },
                {
                  "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://security.gentoo.org/glsa/202310-16",
                  "type": "WEB"
                },
                {
                  "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/security.html",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/advisories/GHSA-jfh8-c2jp-5v3q",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/14/4",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/15/3",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/18/1",
                  "type": "WEB"
                }
              ],
              "max_severity": "critical",
              "fixed_versions": [
                "2.16.0",
                "2.12.2"
              ]
            },
            {
              "id": "GHSA-8489-44mv-ggj8",
              "aliases": [
                "CVE-2021-44832"
              ],
              "summary": "Improper Input Validation and Injection in Apache Log4j2",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.0-beta7"
                        },
                        {
                          "fixed": "2.3.2"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-beta7",
                    "2.0-beta8",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.2",
                    "2.3",
                    "2.3.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.4"
                        },
                        {
                          "fixed": "2.12.4"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.12.3",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.13.0"
                        },
                        {
                          "fixed": "2.17.1"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0",
                    "2.17.0"
                  ]
                }
              ],
              "modified": "2026-06-09T10:45:14.253296471Z",
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
                }
              ],
              "published": "2022-01-04T16:14:20Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44832",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "PACKAGE"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3293",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC",
                  "type": "WEB"
                },
                {
                  "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://security.netapp.com/advisory/ntap-20220104-0001",
                  "type": "WEB"
                },
                {
                  "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujul2022.html",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/28/1",
                  "type": "WEB"
                }
              ],
              "max_severity": "medium",
              "fixed_versions": [
                "2.3.2",
                "2.12.4",
                "2.17.1"
              ]
            },
            {
              "id": "GHSA-jfh8-c2jp-5v3q",
              "kev": {
                "cwes": [
                  "CWE-20",
                  "CWE-400",
                  "CWE-502"
                ],
                "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
                "cve_id": "CVE-2021-44228",
                "product": "Log4j2",
                "due_date": "2021-12-24",
                "date_added": "2021-12-10",
                "vendor_project": "Apache",
                "required_action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
                "short_description": "Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.",
                "vulnerability_name": "Apache Log4j2 Remote Code Execution Vulnerability",
                "known_ransomware_campaign_use": "Known"
              },
              "aliases": [
                "CVE-2021-44228"
              ],
              "summary": "Remote code injection in Log4j",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.13.0"
                        },
                        {
                          "fixed": "2.15.0"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.0-beta9"
                        },
                        {
                          "fixed": "2.3.1"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.2",
                    "2.3"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.4"
                        },
                        {
                          "fixed": "2.12.2"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                }
              ],
              "modified": "2025-10-22T19:37:02.616807Z",
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H"
                }
              ],
              "published": "2021-12-10T00:40:56Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/pull/608",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/github/advisory-database/pull/5501",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
                  "type": "WEB"
                },
                {
                  "url": "https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032",
                  "type": "WEB"
                },
                {
                  "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://seclists.org/fulldisclosure/2022/Dec/2",
                  "type": "WEB"
                },
                {
                  "url": "https://seclists.org/fulldisclosure/2022/Jul/11",
                  "type": "WEB"
                },
                {
                  "url": "https://seclists.org/fulldisclosure/2022/Mar/23",
                  "type": "WEB"
                },
                {
                  "url": "https://security.netapp.com/advisory/ntap-20211210-0007",
                  "type": "WEB"
                },
                {
                  "url": "https://support.apple.com/kb/HT213189",
                  "type": "WEB"
                },
                {
                  "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://twitter.com/kurtseifried/status/1469345530182455296",
                  "type": "WEB"
                },
                {
                  "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001",
                  "type": "WEB"
                },
                {
                  "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228",
                  "type": "WEB"
                },
                {
                  "url": "https://www.debian.org/security/2021/dsa-5020",
                  "type": "WEB"
                },
                {
                  "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.kb.cert.org/vuls/id/930724",
                  "type": "WEB"
                },
                {
                  "url": "https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/advisories/GHSA-7rjr-3q55-vv33",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "PACKAGE"
                },
                {
                  "url": "https://github.com/cisagov/log4j-affected-db",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/tangxiaofeng7/apache-log4j-poc",
                  "type": "WEB"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3198",
                  "type": "WEB"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3201",
                  "type": "WEB"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3214",
                  "type": "WEB"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3221",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/changes-report.html#a2.15.0",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/lookups.html#JndiLookup",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/migration.html",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/security.html",
                  "type": "WEB"
                },
                {
                  "url": "https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://seclists.org/fulldisclosure/2022/Dec/2",
                  "type": "WEB"
                },
                {
                  "url": "http://seclists.org/fulldisclosure/2022/Jul/11",
                  "type": "WEB"
                },
                {
                  "url": "http://seclists.org/fulldisclosure/2022/Mar/23",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/10/1",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/10/2",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/10/3",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/13/1",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/13/2",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/14/4",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/15/3",
                  "type": "WEB"
                }
              ],
              "max_severity": "critical",
              "fixed_versions": [
                "2.15.0",
                "2.3.1",
                "2.12.2"
              ]
            },
            {
              "id": "GHSA-p6xc-xr62-6r2g",
              "aliases": [
                "CVE-2021-45105"
              ],
              "summary": "Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.4.0"
                        },
                        {
                          "fixed": "2.12.3"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.13.0"
                        },
                        {
                          "fixed": "2.17.0"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "0"
                        },
                        {
                          "fixed": "2.3.1"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-alpha1",
                    "2.0-alpha2",
                    "2.0-beta1",
                    "2.0-beta2",
                    "2.0-beta3",
                    "2.0-beta4",
                    "2.0-beta5",
                    "2.0-beta6",
                    "2.0-beta7",
                    "2.0-beta8",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.2",
                    "2.3"
                  ]
                }
              ],
              "modified": "2026-06-09T10:30:14.432177927Z",
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
                }
              ],
              "published": "2021-12-18T18:00:07Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45105",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1541",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujul2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.kb.cert.org/vuls/id/930724",
                  "type": "WEB"
                },
                {
                  "url": "https://www.debian.org/security/2021/dsa-5024",
                  "type": "WEB"
                },
                {
                  "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://security.netapp.com/advisory/ntap-20211218-0001",
                  "type": "WEB"
                },
                {
                  "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/security.html",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00017.html",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/19/1",
                  "type": "WEB"
                }
              ],
              "max_severity": "high",
              "fixed_versions": [
                "2.12.3",
                "2.17.0",
                "2.3.1"
              ]
            },
            {
              "id": "GHSA-vc5p-v9hr-52mj",
              "aliases": [
                "CVE-2025-68161"
              ],
              "summary": "Apache Log4j does not verify the TLS hostname in its Socket Appender",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.0-beta9"
                        },
                        {
                          "fixed": "2.25.3"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.12.3",
                    "2.12.4",
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0",
                    "2.17.0",
                    "2.17.1",
                    "2.17.2",
                    "2.18.0",
                    "2.19.0",
                    "2.2",
                    "2.20.0",
                    "2.21.0",
                    "2.21.1",
                    "2.22.0",
                    "2.22.1",
                    "2.23.0",
                    "2.23.1",
                    "2.24.0",
                    "2.24.1",
                    "2.24.2",
                    "2.24.3",
                    "2.25.0",
                    "2.25.1",
                    "2.25.2",
                    "2.3",
                    "2.3.1",
                    "2.3.2",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                }
              ],
              "modified": "2026-02-04T03:10:00.616806Z",
              "severity": [
                {
                  "type": "CVSS_V4",
                  "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N"
                }
              ],
              "published": "2025-12-18T21:31:44Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68161",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/pull/4002",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/cyclonedx/vdr.xml",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/security.html#CVE-2025-68161",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2025/12/18/1",
                  "type": "WEB"
                }
              ],
              "max_severity": "medium",
              "fixed_versions": [
                "2.25.3"
              ]
            }
          ]
        }
      ],
      "warnings": [],
      "operation": "sbom-check",
      "retrieved_at": "2026-08-02T00:00:00Z",
      "schema_version": "dependency-risk-v1"
    }
  }
}
Cite this page

The pinned URL below renders this page from the snapshot of 2026-09-15 21:20 UTC and does not change; the live page does, every six hours. Data reuse is under CC BY 4.0 (terms).

Plain text

TOLL, "sbom on dependency-risk.use.x402atlas.com", snapshot of 2026-09-15 21:20 UTC. https://tollindex.com/e/dependency-risk-use-x402atlas-com-sbom-d18f47/at/2026-09-15T21-20Z. Accessed [access date].

BibTeX

@misc{toll-e-dependency-risk-use-x402atlas-com-sbom-d18f47-2026-09-15T21-20Z,
  author = {TOLL},
  title = {sbom on dependency-risk.use.x402atlas.com},
  howpublished = {\url{https://tollindex.com/e/dependency-risk-use-x402atlas-com-sbom-d18f47/at/2026-09-15T21-20Z}},
  year = {2026},
  month = {9},
  note = {Pinned view of the snapshot of 2026-09-15 21:20 UTC. Accessed [access date].}
}

Reports and replies about this endpoint

None yet. Anything submitted through the form below is published here with its outcome.

Report an error about sbom, or reply as the named seller

No account, no token. Published unedited with its outcome, upheld or not. Do not include personal data.

Kind

Published as typed. Optional.

10 to 4,000 characters.

Verify with the payee wallet (optional, EVM)

Sign this message with the wallet named on the page and paste the signature; it is checked, stored, never published. TOLL reply about endpoint d18f47bc6aa2827f26861acb1416d78807882e5ff361b358fb6126f32306765f from wallet 0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2

The 0x address named as payee on this page, 42 characters.

The hex signature of the message above, starting 0x.