Open Source Vulnerability Check

x402 Atlas provides real-time x402 analytics for autonomous APIs on Base. Track transactions, discover trends, and analyze the x402 ecosystem.

SearchLiveeip155:8453Exactvia cdp
Package-vulnerability-checkOsvCveCisa-kevSoftware-supply-chain
Calls · 30d
2↑ 7.7%
This endpoint's own trailing-30-day call count, as published by the upstream catalog and snapshotted daily. 30 snapshots so far.
$24.55
Verified settled volume
1,041 settlements proven x402 by their on-chain EIP-3009 marker.
$0.0050
Listed price
As published in the catalog. Always read the live 402 before paying.
2
Calls · 30d
Upstream's own call count for this endpoint, not ours.
1
Unique payers · 30d
Last called 2026-09-15 06:32Z
—
Upstream on-chain volume
Reported by the source catalog.
Paid to
0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2

The wallet the 402 directs payment to. Its whole payment record — every payer, every chain — is on the merchant page.

Asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Provider

The payTo wallet does not resolve to a registered ERC-8004 agent. That is not a verdict on the service — most of the catalog is unregistered.

Accepts

The payment requirements as published to the catalog. Read the live 402 before paying — a price here is a claim, not a quote.

0.005USDC≈ $0.005 USD
on Base · exact scheme

Pay 0.005 USDC on Base to 0x8C12…Df1b2. The signed payment is good for 5 minutes.

USD Coin contract
0x8335…02913
Payment window
5 minutes
As published
5000 smallest units
5000units
on Polygon · exact scheme

That figure is in the token’s smallest units. Roundhouse does not hold this contract’s decimals, so it is shown as published rather than converted.

Token contract
0x3c49…c3359
Payment window
5 minutes
5000units
on Arbitrum · exact scheme

That figure is in the token’s smallest units. Roundhouse does not hold this contract’s decimals, so it is shown as published rather than converted.

Token contract
0xaf88…e5831
Payment window
5 minutes
The catalog’s raw entry
[
  {
    "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "extra": {
      "name": "USD Coin",
      "tier": "standard",
      "version": "2",
      "merchant": "x402Atlas"
    },
    "payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
    "amount": "5000",
    "scheme": "exact",
    "network": "eip155:8453",
    "maxTimeoutSeconds": 300
  },
  {
    "asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
    "extra": {
      "name": "USD Coin",
      "tier": "standard",
      "version": "2",
      "merchant": "x402Atlas"
    },
    "payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
    "amount": "5000",
    "scheme": "exact",
    "network": "eip155:137",
    "maxTimeoutSeconds": 300
  },
  {
    "asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
    "extra": {
      "name": "USD Coin",
      "tier": "standard",
      "version": "2",
      "merchant": "x402Atlas"
    },
    "payTo": "0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2",
    "amount": "5000",
    "scheme": "exact",
    "network": "eip155:42161",
    "maxTimeoutSeconds": 300
  }
]

Extensions

{
  "bazaar": {
    "info": {
      "input": {
        "body": {
          "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1"
        },
        "type": "http",
        "method": "POST",
        "bodyType": "json"
      },
      "output": {
        "type": "json",
        "example": {
          "input": {
            "name": "org.apache.logging.log4j/log4j-core",
            "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1",
            "version": "2.14.1",
            "ecosystem": "maven"
          },
          "stale": false,
          "source": {
            "osv": {
              "name": "OSV.dev"
            },
            "cisa_kev": {
              "name": "Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog",
              "retrieved_at": "2026-08-02T00:00:00Z",
              "date_released": "2026-07-29T18:45:59.5809Z",
              "catalog_version": "2026.07.29"
            }
          },
          "status": "vulnerabilities_found",
          "summary": {
            "kev_count": 2,
            "max_severity": "critical",
            "finding_count": 7
          },
          "findings": [
            {
              "id": "GHSA-3pxv-7cmr-fjr4",
              "aliases": [
                "CVE-2026-34480"
              ],
              "summary": "Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.0-alpha1"
                        },
                        {
                          "fixed": "2.25.4"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-alpha1",
                    "2.0-alpha2",
                    "2.0-beta1",
                    "2.0-beta2",
                    "2.0-beta3",
                    "2.0-beta4",
                    "2.0-beta5",
                    "2.0-beta6",
                    "2.0-beta7",
                    "2.0-beta8",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.12.3",
                    "2.12.4",
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0",
                    "2.17.0",
                    "2.17.1",
                    "2.17.2",
                    "2.18.0",
                    "2.19.0",
                    "2.2",
                    "2.20.0",
                    "2.21.0",
                    "2.21.1",
                    "2.22.0",
                    "2.22.1",
                    "2.23.0",
                    "2.23.1",
                    "2.24.0",
                    "2.24.1",
                    "2.24.2",
                    "2.24.3",
                    "2.25.0",
                    "2.25.1",
                    "2.25.2",
                    "2.25.3",
                    "2.3",
                    "2.3.1",
                    "2.3.2",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "3.0.0-alpha1"
                        },
                        {
                          "last_affected": "3.0.0-beta3"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "3.0.0-alpha1",
                    "3.0.0-beta1",
                    "3.0.0-beta2",
                    "3.0.0-beta3"
                  ]
                }
              ],
              "modified": "2026-04-16T11:29:10.536806482Z",
              "severity": [
                {
                  "type": "CVSS_V4",
                  "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
                }
              ],
              "published": "2026-04-10T18:31:17Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34480",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/pull/4077",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "PACKAGE"
                },
                {
                  "url": "https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/cyclonedx/vdr.xml",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/security.html#CVE-2026-34480",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2026/04/10/9",
                  "type": "WEB"
                }
              ],
              "max_severity": "medium",
              "fixed_versions": [
                "2.25.4"
              ]
            },
            {
              "id": "GHSA-6hg6-v5c8-fphq",
              "aliases": [
                "CVE-2026-34477"
              ],
              "summary": "Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.12.0"
                        },
                        {
                          "fixed": "2.25.4"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.12.3",
                    "2.12.4",
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0",
                    "2.17.0",
                    "2.17.1",
                    "2.17.2",
                    "2.18.0",
                    "2.19.0",
                    "2.20.0",
                    "2.21.0",
                    "2.21.1",
                    "2.22.0",
                    "2.22.1",
                    "2.23.0",
                    "2.23.1",
                    "2.24.0",
                    "2.24.1",
                    "2.24.2",
                    "2.24.3",
                    "2.25.0",
                    "2.25.1",
                    "2.25.2",
                    "2.25.3"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "3.0.0-alpha1"
                        },
                        {
                          "last_affected": "3.0.0-beta3"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "3.0.0-alpha1",
                    "3.0.0-beta1",
                    "3.0.0-beta2",
                    "3.0.0-beta3"
                  ]
                }
              ],
              "modified": "2026-04-17T12:29:10.521430176Z",
              "severity": [
                {
                  "type": "CVSS_V4",
                  "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N"
                }
              ],
              "published": "2026-04-10T18:31:17Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34477",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/pull/4075",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "PACKAGE"
                },
                {
                  "url": "https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/cyclonedx/vdr.xml",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/security.html#CVE-2026-34477",
                  "type": "WEB"
                }
              ],
              "max_severity": "medium",
              "fixed_versions": [
                "2.25.4"
              ]
            },
            {
              "id": "GHSA-7rjr-3q55-vv33",
              "kev": {
                "cwes": [
                  "CWE-917"
                ],
                "notes": "https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046",
                "cve_id": "CVE-2021-45046",
                "product": "Log4j2",
                "due_date": "2023-05-22",
                "date_added": "2023-05-01",
                "vendor_project": "Apache",
                "required_action": "Apply updates per vendor instructions.",
                "short_description": "Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.",
                "vulnerability_name": "Apache Log4j2 Deserialization of Untrusted Data Vulnerability",
                "known_ransomware_campaign_use": "Known"
              },
              "aliases": [
                "CVE-2021-45046"
              ],
              "summary": "Incomplete fix for Apache Log4j vulnerability",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.13.0"
                        },
                        {
                          "fixed": "2.16.0"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "0"
                        },
                        {
                          "fixed": "2.12.2"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-alpha1",
                    "2.0-alpha2",
                    "2.0-beta1",
                    "2.0-beta2",
                    "2.0-beta3",
                    "2.0-beta4",
                    "2.0-beta5",
                    "2.0-beta6",
                    "2.0-beta7",
                    "2.0-beta8",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.2",
                    "2.3",
                    "2.3.1",
                    "2.3.2",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                }
              ],
              "modified": "2025-10-22T19:37:53.742023Z",
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H"
                }
              ],
              "published": "2021-12-14T18:01:28Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45046",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujul2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.openwall.com/lists/oss-security/2021/12/14/4",
                  "type": "WEB"
                },
                {
                  "url": "https://www.kb.cert.org/vuls/id/930724",
                  "type": "WEB"
                },
                {
                  "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.debian.org/security/2021/dsa-5022",
                  "type": "WEB"
                },
                {
                  "url": "https://www.cve.org/CVERecord?id=CVE-2021-44228",
                  "type": "WEB"
                },
                {
                  "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046",
                  "type": "WEB"
                },
                {
                  "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://security.gentoo.org/glsa/202310-16",
                  "type": "WEB"
                },
                {
                  "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/security.html",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/advisories/GHSA-jfh8-c2jp-5v3q",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/14/4",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/15/3",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/18/1",
                  "type": "WEB"
                }
              ],
              "max_severity": "critical",
              "fixed_versions": [
                "2.16.0",
                "2.12.2"
              ]
            },
            {
              "id": "GHSA-8489-44mv-ggj8",
              "aliases": [
                "CVE-2021-44832"
              ],
              "summary": "Improper Input Validation and Injection in Apache Log4j2",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.0-beta7"
                        },
                        {
                          "fixed": "2.3.2"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-beta7",
                    "2.0-beta8",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.2",
                    "2.3",
                    "2.3.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.4"
                        },
                        {
                          "fixed": "2.12.4"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.12.3",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.13.0"
                        },
                        {
                          "fixed": "2.17.1"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0",
                    "2.17.0"
                  ]
                }
              ],
              "modified": "2026-06-09T10:45:14.253296471Z",
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
                }
              ],
              "published": "2022-01-04T16:14:20Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44832",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "PACKAGE"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3293",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC",
                  "type": "WEB"
                },
                {
                  "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://security.netapp.com/advisory/ntap-20220104-0001",
                  "type": "WEB"
                },
                {
                  "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujul2022.html",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/28/1",
                  "type": "WEB"
                }
              ],
              "max_severity": "medium",
              "fixed_versions": [
                "2.3.2",
                "2.12.4",
                "2.17.1"
              ]
            },
            {
              "id": "GHSA-jfh8-c2jp-5v3q",
              "kev": {
                "cwes": [
                  "CWE-20",
                  "CWE-400",
                  "CWE-502"
                ],
                "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
                "cve_id": "CVE-2021-44228",
                "product": "Log4j2",
                "due_date": "2021-12-24",
                "date_added": "2021-12-10",
                "vendor_project": "Apache",
                "required_action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
                "short_description": "Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.",
                "vulnerability_name": "Apache Log4j2 Remote Code Execution Vulnerability",
                "known_ransomware_campaign_use": "Known"
              },
              "aliases": [
                "CVE-2021-44228"
              ],
              "summary": "Remote code injection in Log4j",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.13.0"
                        },
                        {
                          "fixed": "2.15.0"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.0-beta9"
                        },
                        {
                          "fixed": "2.3.1"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.2",
                    "2.3"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.4"
                        },
                        {
                          "fixed": "2.12.2"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                }
              ],
              "modified": "2025-10-22T19:37:02.616807Z",
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H"
                }
              ],
              "published": "2021-12-10T00:40:56Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/pull/608",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/github/advisory-database/pull/5501",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
                  "type": "WEB"
                },
                {
                  "url": "https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032",
                  "type": "WEB"
                },
                {
                  "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://seclists.org/fulldisclosure/2022/Dec/2",
                  "type": "WEB"
                },
                {
                  "url": "https://seclists.org/fulldisclosure/2022/Jul/11",
                  "type": "WEB"
                },
                {
                  "url": "https://seclists.org/fulldisclosure/2022/Mar/23",
                  "type": "WEB"
                },
                {
                  "url": "https://security.netapp.com/advisory/ntap-20211210-0007",
                  "type": "WEB"
                },
                {
                  "url": "https://support.apple.com/kb/HT213189",
                  "type": "WEB"
                },
                {
                  "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://twitter.com/kurtseifried/status/1469345530182455296",
                  "type": "WEB"
                },
                {
                  "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001",
                  "type": "WEB"
                },
                {
                  "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228",
                  "type": "WEB"
                },
                {
                  "url": "https://www.debian.org/security/2021/dsa-5020",
                  "type": "WEB"
                },
                {
                  "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.kb.cert.org/vuls/id/930724",
                  "type": "WEB"
                },
                {
                  "url": "https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/advisories/GHSA-7rjr-3q55-vv33",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "PACKAGE"
                },
                {
                  "url": "https://github.com/cisagov/log4j-affected-db",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/tangxiaofeng7/apache-log4j-poc",
                  "type": "WEB"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3198",
                  "type": "WEB"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3201",
                  "type": "WEB"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3214",
                  "type": "WEB"
                },
                {
                  "url": "https://issues.apache.org/jira/browse/LOG4J2-3221",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/changes-report.html#a2.15.0",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/lookups.html#JndiLookup",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/migration.html",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/security.html",
                  "type": "WEB"
                },
                {
                  "url": "https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html",
                  "type": "WEB"
                },
                {
                  "url": "http://seclists.org/fulldisclosure/2022/Dec/2",
                  "type": "WEB"
                },
                {
                  "url": "http://seclists.org/fulldisclosure/2022/Jul/11",
                  "type": "WEB"
                },
                {
                  "url": "http://seclists.org/fulldisclosure/2022/Mar/23",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/10/1",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/10/2",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/10/3",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/13/1",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/13/2",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/14/4",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/15/3",
                  "type": "WEB"
                }
              ],
              "max_severity": "critical",
              "fixed_versions": [
                "2.15.0",
                "2.3.1",
                "2.12.2"
              ]
            },
            {
              "id": "GHSA-p6xc-xr62-6r2g",
              "aliases": [
                "CVE-2021-45105"
              ],
              "summary": "Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.4.0"
                        },
                        {
                          "fixed": "2.12.3"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.13.0"
                        },
                        {
                          "fixed": "2.17.0"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0"
                  ]
                },
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "0"
                        },
                        {
                          "fixed": "2.3.1"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-alpha1",
                    "2.0-alpha2",
                    "2.0-beta1",
                    "2.0-beta2",
                    "2.0-beta3",
                    "2.0-beta4",
                    "2.0-beta5",
                    "2.0-beta6",
                    "2.0-beta7",
                    "2.0-beta8",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.2",
                    "2.3"
                  ]
                }
              ],
              "modified": "2026-06-09T10:30:14.432177927Z",
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
                }
              ],
              "published": "2021-12-18T18:00:07Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45105",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1541",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujul2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                  "type": "WEB"
                },
                {
                  "url": "https://www.kb.cert.org/vuls/id/930724",
                  "type": "WEB"
                },
                {
                  "url": "https://www.debian.org/security/2021/dsa-5024",
                  "type": "WEB"
                },
                {
                  "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://security.netapp.com/advisory/ntap-20211218-0001",
                  "type": "WEB"
                },
                {
                  "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
                  "type": "WEB"
                },
                {
                  "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/security.html",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00017.html",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf",
                  "type": "WEB"
                },
                {
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2021/12/19/1",
                  "type": "WEB"
                }
              ],
              "max_severity": "high",
              "fixed_versions": [
                "2.12.3",
                "2.17.0",
                "2.3.1"
              ]
            },
            {
              "id": "GHSA-vc5p-v9hr-52mj",
              "aliases": [
                "CVE-2025-68161"
              ],
              "summary": "Apache Log4j does not verify the TLS hostname in its Socket Appender",
              "affected": [
                {
                  "ranges": [
                    {
                      "type": "ECOSYSTEM",
                      "events": [
                        {
                          "introduced": "2.0-beta9"
                        },
                        {
                          "fixed": "2.25.3"
                        }
                      ]
                    }
                  ],
                  "package": {
                    "name": "org.apache.logging.log4j:log4j-core",
                    "purl": "pkg:maven/org.apache.logging.log4j/log4j-core",
                    "ecosystem": "Maven"
                  },
                  "severity": [],
                  "versions": [
                    "2.0",
                    "2.0-beta9",
                    "2.0-rc1",
                    "2.0-rc2",
                    "2.0.1",
                    "2.0.2",
                    "2.1",
                    "2.10.0",
                    "2.11.0",
                    "2.11.1",
                    "2.11.2",
                    "2.12.0",
                    "2.12.1",
                    "2.12.2",
                    "2.12.3",
                    "2.12.4",
                    "2.13.0",
                    "2.13.1",
                    "2.13.2",
                    "2.13.3",
                    "2.14.0",
                    "2.14.1",
                    "2.15.0",
                    "2.16.0",
                    "2.17.0",
                    "2.17.1",
                    "2.17.2",
                    "2.18.0",
                    "2.19.0",
                    "2.2",
                    "2.20.0",
                    "2.21.0",
                    "2.21.1",
                    "2.22.0",
                    "2.22.1",
                    "2.23.0",
                    "2.23.1",
                    "2.24.0",
                    "2.24.1",
                    "2.24.2",
                    "2.24.3",
                    "2.25.0",
                    "2.25.1",
                    "2.25.2",
                    "2.3",
                    "2.3.1",
                    "2.3.2",
                    "2.4",
                    "2.4.1",
                    "2.5",
                    "2.6",
                    "2.6.1",
                    "2.6.2",
                    "2.7",
                    "2.8",
                    "2.8.1",
                    "2.8.2",
                    "2.9.0",
                    "2.9.1"
                  ]
                }
              ],
              "modified": "2026-02-04T03:10:00.616806Z",
              "severity": [
                {
                  "type": "CVSS_V4",
                  "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N"
                }
              ],
              "published": "2025-12-18T21:31:44Z",
              "withdrawn": false,
              "references": [
                {
                  "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68161",
                  "type": "ADVISORY"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/pull/4002",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578",
                  "type": "WEB"
                },
                {
                  "url": "https://github.com/apache/logging-log4j2",
                  "type": "WEB"
                },
                {
                  "url": "https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/cyclonedx/vdr.xml",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName",
                  "type": "WEB"
                },
                {
                  "url": "https://logging.apache.org/security.html#CVE-2025-68161",
                  "type": "WEB"
                },
                {
                  "url": "http://www.openwall.com/lists/oss-security/2025/12/18/1",
                  "type": "WEB"
                }
              ],
              "max_severity": "medium",
              "fixed_versions": [
                "2.25.3"
              ]
            }
          ],
          "warnings": [],
          "operation": "package-check",
          "retrieved_at": "2026-08-02T00:00:00Z",
          "schema_version": "dependency-risk-v1"
        }
      }
    },
    "tags": [
      "package-vulnerability-check",
      "osv",
      "cve",
      "cisa-kev",
      "software-supply-chain"
    ],
    "schema": {
      "type": "object",
      "$schema": "https://json-schema.org/draft/2020-12/schema",
      "required": [
        "input"
      ],
      "properties": {
        "input": {
          "type": "object",
          "required": [
            "type",
            "method",
            "bodyType",
            "body"
          ],
          "properties": {
            "body": {
              "type": "object",
              "required": [
                "purl"
              ],
              "properties": {
                "purl": {
                  "type": "string",
                  "maxLength": 2048,
                  "minLength": 1,
                  "description": "Canonical package URL containing an embedded exact version"
                }
              },
              "additionalProperties": false
            },
            "type": {
              "type": "string",
              "const": "http"
            },
            "method": {
              "enum": [
                "POST"
              ],
              "type": "string"
            },
            "bodyType": {
              "enum": [
                "json",
                "form-data",
                "text"
              ],
              "type": "string"
            }
          },
          "additionalProperties": false
        },
        "output": {
          "type": "object",
          "required": [
            "type"
          ],
          "properties": {
            "type": {
              "type": "string"
            },
            "example": {
              "type": "object",
              "required": [
                "operation",
                "schema_version",
                "source",
                "retrieved_at",
                "stale",
                "warnings",
                "input",
                "status",
                "summary",
                "findings"
              ],
              "properties": {
                "input": {
                  "type": "object",
                  "required": [
                    "ecosystem",
                    "name",
                    "version"
                  ],
                  "properties": {
                    "name": {
                      "type": "string",
                      "description": "Exact package-manager name"
                    },
                    "purl": {
                      "type": "string",
                      "description": "Canonical input purl when the caller used purl form; otherwise omitted"
                    },
                    "version": {
                      "type": "string",
                      "description": "Exact queried package version"
                    },
                    "ecosystem": {
                      "type": "string",
                      "description": "Exact package ecosystem; purl types remain canonical lowercase identifiers"
                    }
                  },
                  "description": "Canonical exact package/version identity",
                  "additionalProperties": false
                },
                "stale": {
                  "type": "boolean",
                  "description": "True only when a prior validated CISA KEV snapshot is served after refresh failure; OSV result completeness is never silently marked stale"
                },
                "_atlas": {
                  "type": "object",
                  "required": [
                    "docs"
                  ],
                  "properties": {
                    "docs": {
                      "type": "string",
                      "format": "uri",
                      "maxLength": 512,
                      "description": "Documentation URL for this bridge"
                    },
                    "related": {
                      "type": "array",
                      "items": {
                        "type": "object",
                        "required": [
                          "bridge",
                          "url",
                          "docs",
                          "summary"
                        ],
                        "properties": {
                          "url": {
                            "type": "string",
                            "format": "uri",
                            "maxLength": 512,
                            "description": "Related route URL"
                          },
                          "docs": {
                            "type": "string",
                            "format": "uri",
                            "maxLength": 512,
                            "description": "Related bridge documentation URL"
                          },
                          "bridge": {
                            "type": "string",
                            "maxLength": 64,
                            "description": "Related bridge name"
                          },
                          "summary": {
                            "type": "string",
                            "maxLength": 256,
                            "description": "Short capability summary"
                          }
                        },
                        "description": "One related Atlas route",
                        "additionalProperties": false
                      },
                      "maxItems": 3,
                      "description": "Bounded related Atlas routes"
                    }
                  },
                  "description": "Atlas documentation and related-route metadata added after deployment",
                  "additionalProperties": false
                },
                "source": {
                  "type": "object",
                  "required": [
                    "osv",
                    "cisa_kev"
                  ],
                  "properties": {
                    "osv": {
                      "type": "object",
                      "required": [
                        "name"
                      ],
                      "properties": {
                        "name": {
                          "type": "string",
                          "const": "OSV.dev",
                          "description": "Official OSV.dev vulnerability record aggregator"
                        }
                      },
                      "description": "OSV source identity; individual finding times carry record publication and modification semantics",
                      "additionalProperties": false
                    },
                    "cisa_kev": {
                      "type": "object",
                      "required": [
                        "name",
                        "catalog_version",
                        "date_released",
                        "retrieved_at"
                      ],
                      "properties": {
                        "name": {
                          "type": "string",
                          "const": "Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog",
                          "description": "Official CISA KEV source name"
                        },
                        "retrieved_at": {
                          "type": "string",
                          "format": "date-time",
                          "description": "UTC time this exact validated KEV snapshot was retrieved"
                        },
                        "date_released": {
                          "type": "string",
                          "description": "Release time published in the validated CISA feed"
                        },
                        "catalog_version": {
                          "type": "string",
                          "description": "Catalog version published in the validated CISA feed"
                        }
                      },
                      "description": "Validated CISA Known Exploited Vulnerabilities snapshot used for exact CVE enrichment",
                      "additionalProperties": false
                    }
                  },
                  "description": "Named public sources and the exact CISA KEV snapshot used for this response",
                  "additionalProperties": false
                },
                "status": {
                  "enum": [
                    "no_known_vulnerabilities",
                    "vulnerabilities_found"
                  ],
                  "type": "string",
                  "description": "Complete named-source result: no_known_vulnerabilities means OSV returned no matching active record, not that the dependency is safe"
                },
                "summary": {
                  "type": "object",
                  "required": [
                    "finding_count",
                    "kev_count",
                    "max_severity"
                  ],
                  "properties": {
                    "kev_count": {
                      "type": "integer",
                      "maximum": 16,
                      "minimum": 0,
                      "description": "Active findings with an exact KEV CVE match"
                    },
                    "max_severity": {
                      "enum": [
                        "unknown",
                        "low",
                        "medium",
                        "high",
                        "critical"
                      ],
                      "type": "string",
                      "description": "Highest parseable published CVSS severity among active findings"
                    },
                    "finding_count": {
                      "type": "integer",
                      "maximum": 16,
                      "minimum": 0,
                      "description": "Active non-withdrawn finding count"
                    }
                  },
                  "description": "Summary of active non-withdrawn findings",
                  "additionalProperties": false
                },
                "findings": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "required": [
                      "id",
                      "aliases",
                      "modified",
                      "withdrawn",
                      "affected",
                      "references",
                      "severity",
                      "max_severity",
                      "fixed_versions"
                    ],
                    "properties": {
                      "id": {
                        "type": "string",
                        "description": "Authoritative OSV record identifier"
                      },
                      "kev": {
                        "type": "object",
                        "required": [
                          "cve_id",
                          "vendor_project",
                          "product",
                          "vulnerability_name",
                          "date_added",
                          "short_description",
                          "required_action",
                          "due_date",
                          "cwes"
                        ],
                        "properties": {
                          "cwes": {
                            "type": "array",
                            "items": {
                              "type": "string"
                            },
                            "description": "CWE identifiers published by CISA"
                          },
                          "notes": {
                            "type": "string",
                            "description": "Additional CISA KEV notes when supplied"
                          },
                          "cve_id": {
                            "type": "string",
                            "description": "Exact CVE identifier matched in the CISA KEV catalog"
                          },
                          "product": {
                            "type": "string",
                            "description": "Affected product label published by CISA"
                          },
                          "due_date": {
                            "type": "string",
                            "description": "CISA KEV due date for covered federal agencies"
                          },
                          "date_added": {
                            "type": "string",
                            "description": "Date CISA added the CVE to KEV"
                          },
                          "vendor_project": {
                            "type": "string",
                            "description": "Vendor or project label published by CISA"
                          },
                          "required_action": {
                            "type": "string",
                            "description": "Required action text published by CISA; caller remediation review is still required"
                          },
                          "short_description": {
                            "type": "string",
                            "description": "Short vulnerability description published by CISA"
                          },
                          "vulnerability_name": {
                            "type": "string",
                            "description": "CISA KEV vulnerability name"
                          },
                          "known_ransomware_campaign_use": {
                            "type": "string",
                            "description": "CISA's published ransomware-campaign-use value when supplied"
                          }
                        },
                        "description": "Exact CISA KEV match on a syntactically valid CVE ID or alias; omitted rather than null when no exact match exists",
                        "additionalProperties": false
                      },
                      "aliases": {
                        "type": "array",
                        "items": {
                          "type": "string"
                        },
                        "description": "Deduplicated lexical aliases published by OSV"
                      },
                      "summary": {
                        "type": "string",
                        "description": "Bounded OSV summary"
                      },
                      "affected": {
                        "type": "array",
                        "items": {
                          "type": "object",
                          "required": [
                            "package",
                            "ranges",
                            "versions",
                            "severity"
                          ],
                          "properties": {
                            "ranges": {
                              "type": "array",
                              "items": {
                                "type": "object",
                                "required": [
                                  "type",
                                  "events"
                                ],
                                "properties": {
                                  "repo": {
                                    "type": "string",
                                    "description": "Repository identifier published by OSV for a GIT range"
                                  },
                                  "type": {
                                    "type": "string",
                                    "description": "OSV range type such as SEMVER, ECOSYSTEM, or GIT"
                                  },
                                  "events": {
                                    "type": "array",
                                    "items": {
                                      "type": "object",
                                      "properties": {
                                        "fixed": {
                                          "type": "string",
                                          "description": "OSV range event explicitly marking a fixed version"
                                        },
                                        "limit": {
                                          "type": "string",
                                          "description": "OSV range event upper limit when supplied"
                                        },
                                        "introduced": {
                                          "type": "string",
                                          "description": "OSV range event marking an introduced version"
                                        },
                                        "last_affected": {
                                          "type": "string",
                                          "description": "OSV range event marking the last affected version"
                                        }
                                      },
                                      "description": "One OSV range event; exactly one event field is normally supplied by the source",
                                      "additionalProperties": false
                                    },
                                    "description": "Ordered OSV range events; the bridge does not infer ecosystem version ordering"
                                  }
                                },
                                "description": "One affected version range published by OSV",
                                "additionalProperties": false
                              },
                              "description": "Affected ranges retained in OSV source order"
                            },
                            "package": {
                              "type": "object",
                              "properties": {
                                "name": {
                                  "type": "string",
                                  "description": "Exact package name published by OSV"
                                },
                                "purl": {
                                  "type": "string",
                                  "description": "Package URL published by OSV when supplied"
                                },
                                "ecosystem": {
                                  "type": "string",
                                  "description": "Exact OSV ecosystem identifier"
                                }
                              },
                              "description": "Exact affected package identity published by OSV",
                              "additionalProperties": false
                            },
                            "severity": {
                              "type": "array",
                              "items": {
                                "type": "object",
                                "required": [
                                  "type",
                                  "score"
                                ],
                                "properties": {
                                  "type": {
                                    "type": "string",
                                    "description": "OSV-declared score type such as CVSS_V3"
                                  },
                                  "score": {
                                    "type": "string",
                                    "description": "Original published vector; malformed or mismatched vectors are retained but score as unknown"
                                  }
                                },
                                "description": "One severity vector exactly as published by OSV",
                                "additionalProperties": false
                              },
                              "description": "Severity vectors attached to this affected package entry"
                            },
                            "versions": {
                              "type": "array",
                              "items": {
                                "type": "string"
                              },
                              "description": "Affected versions explicitly enumerated by OSV"
                            }
                          },
                          "description": "One OSV affected package entry retained in source order",
                          "additionalProperties": false
                        },
                        "description": "Bounded OSV affected package/range/event data in source order"
                      },
                      "modified": {
                        "type": "string",
                        "description": "OSV modification time string"
                      },
                      "severity": {
                        "type": "array",
                        "items": {
                          "type": "object",
                          "required": [
                            "type",
                            "score"
                          ],
                          "properties": {
                            "type": {
                              "type": "string",
                              "description": "OSV-declared score type such as CVSS_V3"
                            },
                            "score": {
                              "type": "string",
                              "description": "Original published vector; malformed or mismatched vectors are retained but score as unknown"
                            }
                          },
                          "description": "One severity vector exactly as published by OSV",
                          "additionalProperties": false
                        },
                        "maxItems": 16,
                        "description": "At most 16 published top-level OSV severity vectors"
                      },
                      "published": {
                        "type": "string",
                        "description": "OSV publication time string when supplied"
                      },
                      "withdrawn": {
                        "type": "boolean",
                        "description": "Whether OSV withdrew the record; withdrawn findings remain visible but do not count in the active summary"
                      },
                      "references": {
                        "type": "array",
                        "items": {
                          "type": "object",
                          "required": [
                            "type",
                            "url"
                          ],
                          "properties": {
                            "url": {
                              "type": "string",
                              "description": "Reference URL supplied by OSV as untrusted provenance data; never fetched by this bridge"
                            },
                            "type": {
                              "type": "string",
                              "description": "OSV reference classification such as ADVISORY, FIX, REPORT, or WEB"
                            }
                          },
                          "description": "One OSV-published reference retained as provenance data",
                          "additionalProperties": false
                        },
                        "description": "Bounded references published by OSV; URLs are untrusted data returned for provenance and are never fetched by this bridge"
                      },
                      "max_severity": {
                        "enum": [
                          "unknown",
                          "low",
                          "medium",
                          "high",
                          "critical"
                        ],
                        "type": "string",
                        "description": "Highest severity derived only from a parseable declared CVSS vector"
                      },
                      "withdrawn_at": {
                        "type": "string",
                        "description": "OSV withdrawal time string, present only when supplied"
                      },
                      "fixed_versions": {
                        "type": "array",
                        "items": {
                          "type": "string"
                        },
                        "description": "Only explicit fixed events for the matching package, deduplicated in OSV source order; [] means OSV supplied no fixed event, not that no fix exists"
                      }
                    },
                    "description": "One complete normalized OSV vulnerability finding, limited to 48 KiB after JSON encoding, with optional exact CISA KEV enrichment",
                    "additionalProperties": false
                  },
                  "maxItems": 16,
                  "description": "Complete normalized OSV findings sorted lexically by authoritative OSV ID; at most 16 from the one supported OSV page and always [] when none"
                },
                "warnings": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "description": "Bounded warning intended for caller action or interpretation"
                  },
                  "description": "Freshness and interpretation warnings; always [] when none"
                },
                "operation": {
                  "type": "string",
                  "const": "package-check",
                  "description": "Stable route operation identifier"
                },
                "retrieved_at": {
                  "type": "string",
                  "format": "date-time",
                  "description": "UTC time this bridge completed the response; this is not an OSV publication or modification time"
                },
                "schema_version": {
                  "type": "string",
                  "const": "dependency-risk-v1",
                  "description": "Version of the normalized Dependency Risk response contract"
                }
              },
              "description": "Complete transactional Dependency Risk response, limited to the native budget reserved below the 512 KiB deployed wire ceiling",
              "additionalProperties": false
            }
          }
        }
      }
    },
    "category": "security"
  }
}

Provenance

Seen in the source catalog
2026-09-15 06:32Z
Last indexed by Roundhouse
2026-09-24 20:50Z
Last enriched (probe, favicon, geo)
2026-09-20 13:15Z
x402 version
2
Max timeout
300s
Liveness probe
HTTP 405
Report

Hand this page to an agent

Copy the prompt and paste it into Claude, an MCP client or your own agent — it will vet this service and call it over the free read API. No key, no account.

GET api.roundhouseai.io/v0/endpoints

This endpoint's own trailing-30-day call count, as published by the upstream catalog and snapshotted daily. 30 snapshots so far. Verified volume counts only settlements with an on-chain EIP-3009 marker.

Open skill.md
Show the prompt
Using Roundhouse, look up the x402 service Open Source Vulnerability Check and tell me whether it is
worth paying: what a call costs, whether the endpoint answered when last probed, and what
its payment record actually shows.

curl -s 'https://api.roundhouseai.io/v0/endpoints?q=Open%20Source%20Vulnerability%20Check'
curl -s 'https://api.roundhouseai.io/v0/merchants/<the payTo wallet returned above>'

Then call it: read the price from the live 402 at https://dependency-risk.use.x402atlas.com/package, never from
a cached figure, and pay with an x402 client.

The /v0 API needs an API key (`authorization: Bearer rh_live_…`) on everything except
/v0/unified* and /v0/endpoints. Mint a personal key for $0.01 at GET https://api.roundhouseai.io/v0/test/x402,
or use an organization key from https://roundhouseai.io/dashboard/team.

If you do not have Roundhouse tools or skills installed, read
https://roundhouseai.io/skill.md first — it is the whole procedure.