PUT/v1/vulnerability

Create a vulnerability

Creates a vulnerability record with its identifiers, affected components, and scoring data. Include friendlyVulnId, source, uuid, and vulnId; you also need VULNERABILITY_MANAGEMENT or VULNERABILITY_MANAGEMENT_CREATE permission.

45 body fields

Vulnerability data to create. Include friendlyVulnId, source, uuid, and vulnId.

affectedActiveProjectCountintegeroptional
The number of active projects affected by the vulnerability.
affectedComponentsarray<object>optional
Component identities and version ranges affected by the vulnerability, with optional version attribution details.
affectedInactiveProjectCountintegeroptional
The number of inactive projects affected by the vulnerability.
affectedProjectCountintegeroptional
The total number of projects affected by the vulnerability.
aliasesarray<object>optional
Alternative vulnerability identifiers, including CVE, GHSA, OSV, Snyk, and other source identifiers.
componentsarray<object>optional
Component records associated with the vulnerability, including classifier, name, project, and UUID. The component `classifier` is constrained to the supported classifier values; hashes such as `blake2b_256`, `blake2b_384`, and `blake2b_512` must contain 64, 96, and 128 lowercase hexadecimal characters respectively.
createdstringoptional
The vulnerability creation timestamp in date-time format.
creditsstringoptional
Credit or attribution text for the vulnerability.
cvssV2BaseScorenumberoptional
The CVSS v2 base score.
cvssV2ExploitabilitySubScorenumberoptional
The CVSS v2 exploitability subscore.
cvssV2ImpactSubScorenumberoptional
The CVSS v2 impact subscore.
cvssV2Vectorstringoptional
The CVSS v2 vector string.
cvssV3BaseScorenumberoptional
The CVSS v3 base score.
cvssV3ExploitabilitySubScorenumberoptional
The CVSS v3 exploitability subscore.
cvssV3ImpactSubScorenumberoptional
The CVSS v3 impact subscore.
cvssV3Vectorstringoptional
cvssV4Scorenumberoptional
cvssV4Vectorstringoptional
cwesarray<object>optional
descriptionstringoptional
detailstringoptional
epssobjectoptional
epssPercentilenumberoptional
epssScorenumberoptional
friendlyVulnIdstringrequired
The human-readable identifier for the vulnerability.
isKevbooleanoptional
owaspRRBusinessImpactScorenumberoptional
owaspRRLikelihoodScorenumberoptional
owaspRRTechnicalImpactScorenumberoptional
owaspRRVectorstringoptional
patchedVersionsstringoptional
publishedstringoptional
recommendationstringoptional
referencesstringoptional
rejectedstringoptional
serviceComponentsarray<object>optional
severitystringoptional
Allowed:CRITICALHIGHMEDIUMLOWINFOUNASSIGNED
sourcestringrequired
The source that supplies the vulnerability record.
subTitlestringoptional
tagsarray<object>optional
titlestringoptional
updatedstringoptional
uuidstringrequired
The UUID for the vulnerability record.
vulnIdstringrequired
The vulnerability identifier assigned by its source.
vulnerableVersionsstringoptional

3 status codes
201Returns the created vulnerability object, including its identifiers, affected projects and components, aliases, and scoring data.
affectedActiveProjectCountintegeroptional
affectedComponentsarray<object>optional
affectedInactiveProjectCountintegeroptional
affectedProjectCountintegeroptional
aliasesarray<object>optional
componentsarray<object>optional
createdstringoptional
creditsstringoptional
cvssV2BaseScorenumberoptional
cvssV2ExploitabilitySubScorenumberoptional
cvssV2ImpactSubScorenumberoptional
cvssV2Vectorstringoptional
cvssV3BaseScorenumberoptional
cvssV3ExploitabilitySubScorenumberoptional
cvssV3ImpactSubScorenumberoptional
cvssV3Vectorstringoptional
cvssV4Scorenumberoptional
cvssV4Vectorstringoptional
cwesarray<object>optional
descriptionstringoptional
detailstringoptional
epssobjectoptional
epssPercentilenumberoptional
epssScorenumberoptional
friendlyVulnIdstringrequired
isKevbooleanoptional
owaspRRBusinessImpactScorenumberoptional
owaspRRLikelihoodScorenumberoptional
owaspRRTechnicalImpactScorenumberoptional
owaspRRVectorstringoptional
patchedVersionsstringoptional
publishedstringoptional
recommendationstringoptional
referencesstringoptional
rejectedstringoptional
serviceComponentsarray<object>optional
severitystringoptional
Allowed:CRITICALHIGHMEDIUMLOWINFOUNASSIGNED
sourcestringrequired
subTitlestringoptional
tagsarray<object>optional
titlestringoptional
updatedstringoptional
uuidstringrequired
vulnIdstringrequired
vulnerableVersionsstringoptional
401Returned when you lack the required vulnerability management permission.
409Returned when a vulnerability with the specified `vulnId` already exists.

Error handling

A 401 is returned when you lack VULNERABILITY_MANAGEMENT or VULNERABILITY_MANAGEMENT_CREATE permission. A 409 is returned when a vulnerability with the supplied vulnId already exists. The body must include friendlyVulnId, source, uuid, and vulnId.