Skip to content
Start here

Get reviewed vulnerability report

GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos/{repo_id}/scans/{scan_id}/report

Gets the repository projection of the active operator-reviewed scan report. scan_id is the customer scan’s stable request ID.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Path ParametersExpand Collapse
account_id: string
repo_id: string
formatuuid
scan_id: string
formatuuid
ReturnsExpand Collapse
errors: array of ResponseInfo { code, message, documentation_url, source }
code: number
minimum1000
message: string
documentation_url: optional string
source: optional object { pointer }
pointer: optional string
messages: array of ResponseInfo { code, message, documentation_url, source }
code: number
minimum1000
message: string
documentation_url: optional string
source: optional object { pointer }
pointer: optional string
result: object { publication, report, repository_id, scan_id }
publication: object { published_at, revision_id, version }
published_at: string
formatdate-time
revision_id: string
formatuuid
version: number
minimum1
report: object { findings, overall_severity, repository_id, 5 more }
findings: array of object { id, conditions, cwe, 17 more }
id: string
maxLength128
minLength1
conditions: array of string
cwe: string
minLength1
impact: string
maxLength4000
minLength1
location: object { file, line, route }
file: string
minLength1
line: number
minimum1
route: string
reachability: array of object { consumer, reachable, via }
consumer: string
minLength1
reachable: boolean
via: string
remediation: object { code_changes, strategy }
code_changes: string
strategy: string
minLength1
root_cause: string
maxLength4000
minLength1
severity: "critical" or "high" or "medium" or 2 more
One of the following:
"critical"
"high"
"medium"
"low"
"info"
severity_basis: string
minLength1
summary: string
maxLength4000
minLength1
telemetry: object { references, state }
references: array of string
state: "no_route" or "no_telemetry" or "no_match" or "matched"
One of the following:
"no_route"
"no_telemetry"
"no_match"
"matched"
title: string
maxLength200
minLength1
trace: array of object { line, path, scope, why }
line: number
minimum1
path: string
minLength1
scope: string
why: string
waf_rules: object { broad, targeted }
broad: object { action, confidence, description, 4 more }
action: "block" or "managed_challenge" or "js_challenge" or "log"
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: "low" or "medium" or "high"
One of the following:
"low"
"medium"
"high"
description: string
minLength1
expression: string
maxLength4096
minLength1
false_positive_risk: string
minLength1
name: string
maxLength25
minLength1
rationale: string
minLength1
targeted: object { action, confidence, description, 4 more }
action: "block" or "managed_challenge" or "js_challenge" or "log"
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: "low" or "medium" or "high"
One of the following:
"low"
"medium"
"high"
description: string
minLength1
expression: string
maxLength4096
minLength1
false_positive_risk: string
minLength1
name: string
maxLength25
minLength1
rationale: string
minLength1
attacker_position: optional "external" or "authenticated" or "internal" or "post_compromise"

Least-privileged position required to trigger the finding. Optional on legacy report revisions.

One of the following:
"external"
"authenticated"
"internal"
"post_compromise"
open_question: optional string

One bounded unresolved proof question. Optional on legacy report revisions.

maxLength500
proof_method: optional "structural" or "experimental" or "acquired_source" or 2 more

Method used or needed to close the proof. Optional on legacy report revisions.

One of the following:
"structural"
"experimental"
"acquired_source"
"public_knowledge"
"team_question"
proof_state: optional "closed" or "pending_source" or "pending_public" or 2 more

Current proof lifecycle state. Optional on legacy report revisions.

One of the following:
"closed"
"pending_source"
"pending_public"
"pending_experiment"
"pending_team"
overall_severity: "critical" or "high" or "medium" or 2 more
One of the following:
"critical"
"high"
"medium"
"low"
"info"
repository_id: string
formatuuid
repository_name: string
minLength1
summary: string
maxLength4000
minLength1
traffic_context: object { http, target, waf, web_assets }
http: object { error_paths, hot_paths, request_volume }
error_paths: array of object { id, hits, host, 2 more }
id: string
minLength1
hits: number
minimum0
host: string
minLength1
path: string
minLength1
status: number
maximum599
minimum100
hot_paths: array of object { id, hits, host, 2 more }
id: string
minLength1
hits: number
minimum0
host: string
minLength1
path: string
minLength1
top_status: number
maximum599
minimum100
request_volume: number
minimum0
target: object { hosts, kind, telemetry_window }
hosts: array of string
kind: "worker" or "origin"
One of the following:
"worker"
"origin"
telemetry_window: optional object { end, start }

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: string
formatdate-time
start: string
formatdate-time
waf: object { hit_volume, rules }
hit_volume: number
minimum0
rules: array of object { id, hit_volume, paths, 2 more }
id: string
minLength1
hit_volume: number
minimum0
paths: array of object { id, hit_volume, host, path }
id: string
minLength1
hit_volume: number
minimum0
host: string
minLength1
path: string
minLength1
rule_id: string
minLength1
rule_version: number
minimum0
web_assets: object { operations, paths, risk_types }
operations: array of object { id, endpoint, host, 3 more }
id: string
minLength1
endpoint: string
minLength1
host: string
minLength1
method: string
minLength1
risk_labels: array of object { description, name }
description: string
name: string
minLength1
performance: optional object { avg_origin_latency_ms, error_rate, estimated_requests }
avg_origin_latency_ms: number
minimum0
error_rate: number
maximum1
minimum0
estimated_requests: number
minimum0
paths: array of object { id, avg_origin_latency_ms, error_rate, 3 more }
id: string
minLength1
avg_origin_latency_ms: number
minimum0
error_rate: number
maximum1
minimum0
estimated_requests: number
minimum0
host: string
minLength1
path: string
minLength1
risk_types: array of object { description, name, operation_count }
description: string
name: string
minLength1
operation_count: number
minimum0
limitations: optional array of string
repository_id: string
formatuuid
scan_id: string
maxLength128
minLength1
success: true

Get reviewed vulnerability report

curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/managed-defense/vulnerability-discovery/repos/$REPO_ID/scans/$SCAN_ID/report \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "publication": {
      "published_at": "2019-12-27T18:11:19.117Z",
      "revision_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "version": 1
    },
    "report": {
      "findings": [
        {
          "id": "x",
          "conditions": [
            "string"
          ],
          "cwe": "x",
          "impact": "x",
          "location": {
            "file": "x",
            "line": 1,
            "route": "route"
          },
          "reachability": [
            {
              "consumer": "x",
              "reachable": true,
              "via": "via"
            }
          ],
          "remediation": {
            "code_changes": "code_changes",
            "strategy": "x"
          },
          "root_cause": "x",
          "severity": "critical",
          "severity_basis": "x",
          "summary": "x",
          "telemetry": {
            "references": [
              "x"
            ],
            "state": "no_route"
          },
          "title": "x",
          "trace": [
            {
              "line": 1,
              "path": "x",
              "scope": "scope",
              "why": "why"
            }
          ],
          "waf_rules": {
            "broad": {
              "action": "block",
              "confidence": "low",
              "description": "x",
              "expression": "x",
              "false_positive_risk": "x",
              "name": "x",
              "rationale": "x"
            },
            "targeted": {
              "action": "block",
              "confidence": "low",
              "description": "x",
              "expression": "x",
              "false_positive_risk": "x",
              "name": "x",
              "rationale": "x"
            }
          },
          "attacker_position": "external",
          "external_links": [
            {
              "title": "x",
              "url": "https://example.com"
            }
          ],
          "open_question": "open_question",
          "proof_method": "structural",
          "proof_state": "closed"
        }
      ],
      "overall_severity": "critical",
      "repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "repository_name": "x",
      "summary": "x",
      "traffic_context": {
        "http": {
          "error_paths": [
            {
              "id": "x",
              "hits": 0,
              "host": "x",
              "path": "x",
              "status": 100
            }
          ],
          "hot_paths": [
            {
              "id": "x",
              "hits": 0,
              "host": "x",
              "path": "x",
              "top_status": 100
            }
          ],
          "request_volume": 0
        },
        "target": {
          "hosts": [
            "x"
          ],
          "kind": "worker",
          "telemetry_window": {
            "end": "2019-12-27T18:11:19.117Z",
            "start": "2019-12-27T18:11:19.117Z"
          }
        },
        "waf": {
          "hit_volume": 0,
          "rules": [
            {
              "id": "x",
              "hit_volume": 0,
              "paths": [
                {
                  "id": "x",
                  "hit_volume": 0,
                  "host": "x",
                  "path": "x"
                }
              ],
              "rule_id": "x",
              "rule_version": 0
            }
          ]
        },
        "web_assets": {
          "operations": [
            {
              "id": "x",
              "endpoint": "x",
              "host": "x",
              "method": "x",
              "risk_labels": [
                {
                  "description": "description",
                  "name": "x"
                }
              ],
              "performance": {
                "avg_origin_latency_ms": 0,
                "error_rate": 0,
                "estimated_requests": 0
              }
            }
          ],
          "paths": [
            {
              "id": "x",
              "avg_origin_latency_ms": 0,
              "error_rate": 0,
              "estimated_requests": 0,
              "host": "x",
              "path": "x"
            }
          ],
          "risk_types": [
            {
              "description": "description",
              "name": "x",
              "operation_count": 0
            }
          ]
        }
      },
      "external_links": [
        {
          "title": "x",
          "url": "https://example.com"
        }
      ],
      "limitations": [
        "x"
      ]
    },
    "repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "scan_id": "x"
  },
  "success": true
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "publication": {
      "published_at": "2019-12-27T18:11:19.117Z",
      "revision_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "version": 1
    },
    "report": {
      "findings": [
        {
          "id": "x",
          "conditions": [
            "string"
          ],
          "cwe": "x",
          "impact": "x",
          "location": {
            "file": "x",
            "line": 1,
            "route": "route"
          },
          "reachability": [
            {
              "consumer": "x",
              "reachable": true,
              "via": "via"
            }
          ],
          "remediation": {
            "code_changes": "code_changes",
            "strategy": "x"
          },
          "root_cause": "x",
          "severity": "critical",
          "severity_basis": "x",
          "summary": "x",
          "telemetry": {
            "references": [
              "x"
            ],
            "state": "no_route"
          },
          "title": "x",
          "trace": [
            {
              "line": 1,
              "path": "x",
              "scope": "scope",
              "why": "why"
            }
          ],
          "waf_rules": {
            "broad": {
              "action": "block",
              "confidence": "low",
              "description": "x",
              "expression": "x",
              "false_positive_risk": "x",
              "name": "x",
              "rationale": "x"
            },
            "targeted": {
              "action": "block",
              "confidence": "low",
              "description": "x",
              "expression": "x",
              "false_positive_risk": "x",
              "name": "x",
              "rationale": "x"
            }
          },
          "attacker_position": "external",
          "external_links": [
            {
              "title": "x",
              "url": "https://example.com"
            }
          ],
          "open_question": "open_question",
          "proof_method": "structural",
          "proof_state": "closed"
        }
      ],
      "overall_severity": "critical",
      "repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "repository_name": "x",
      "summary": "x",
      "traffic_context": {
        "http": {
          "error_paths": [
            {
              "id": "x",
              "hits": 0,
              "host": "x",
              "path": "x",
              "status": 100
            }
          ],
          "hot_paths": [
            {
              "id": "x",
              "hits": 0,
              "host": "x",
              "path": "x",
              "top_status": 100
            }
          ],
          "request_volume": 0
        },
        "target": {
          "hosts": [
            "x"
          ],
          "kind": "worker",
          "telemetry_window": {
            "end": "2019-12-27T18:11:19.117Z",
            "start": "2019-12-27T18:11:19.117Z"
          }
        },
        "waf": {
          "hit_volume": 0,
          "rules": [
            {
              "id": "x",
              "hit_volume": 0,
              "paths": [
                {
                  "id": "x",
                  "hit_volume": 0,
                  "host": "x",
                  "path": "x"
                }
              ],
              "rule_id": "x",
              "rule_version": 0
            }
          ]
        },
        "web_assets": {
          "operations": [
            {
              "id": "x",
              "endpoint": "x",
              "host": "x",
              "method": "x",
              "risk_labels": [
                {
                  "description": "description",
                  "name": "x"
                }
              ],
              "performance": {
                "avg_origin_latency_ms": 0,
                "error_rate": 0,
                "estimated_requests": 0
              }
            }
          ],
          "paths": [
            {
              "id": "x",
              "avg_origin_latency_ms": 0,
              "error_rate": 0,
              "estimated_requests": 0,
              "host": "x",
              "path": "x"
            }
          ],
          "risk_types": [
            {
              "description": "description",
              "name": "x",
              "operation_count": 0
            }
          ]
        }
      },
      "external_links": [
        {
          "title": "x",
          "url": "https://example.com"
        }
      ],
      "limitations": [
        "x"
      ]
    },
    "repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "scan_id": "x"
  },
  "success": true
}