{"definitionRoot":"12831daeda56b39de1faea4120f20e1d9151890b173290e3fde209a5c495cff6","docsPath":"/docs/VULNERABILITY_RECORD_LOOKUP.json","errors":[{"code":null,"description":"The request field is invalid.","status":400},{"code":null,"description":"Payment Required - an x402 v2 offer in the PAYMENT-REQUIRED header and body.","status":402},{"code":null,"description":"The result could not be delivered.","status":422},{"code":null,"description":"The seller or the product quote path is not currently admitting this request.","status":503}],"examples":{"deliverable":null,"detail":"Concrete request/deliverable examples are omitted until real settled evidence supplies them; the no-fake-demand rule forbids inventing sample payloads. The envelope shapes above are exact.","request":null,"state":"OMITTED_UNTIL_REAL_EVIDENCE"},"family":"RISK","familyTitle":"Arbiter Risk","freshness":{"evidenceCutoff":"Every delivered envelope states its own evidenceCutoff; requests may pin evidenceCutoff at or before quote time.","freshnessClass":"CACHEABLE_SNAPSHOT","latencyClass":"STANDARD","machineVersion":"df8b5c0c","outputDomainKind":null,"provenance":"The deliverable carries its own uncertainty statement; citations are opaque content hashes for the public evidence used."},"inputSchema":{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"cveId":{"description":"The CVE identifier, e.g. CVE-2021-44228: CVE-, a year, -, then 4 digits, or 5 to 19 digits without a leading zero. Checked before any payment; an id NVD holds no record of is delivered as NOT_FOUND.","type":"string"}},"required":["cveId"],"type":"object","x-arbiter-contentType":"application/json","x-arbiter-schemaVersion":"1.0.0"},"method":"POST","operationId":"agenthubmachinevulnerability_record_lookup","outputSchema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"citations":{"description":"Content hashes of Arbiter's archived official-record readings this deliverable was rendered from.","items":{},"type":"array"},"observedAt":{"description":"ISO-8601 instant of the newest official read behind this deliverable.","type":"string"},"program":{"description":"Program identity: {id, version, programRoot, registryRoot}.","type":"object"},"record":{"description":"CVE record: {status: FOUND|NOT_FOUND, cveId, nvdUrl, sourceIdentifier, vulnStatus, published, lastModified (NVD UTC timestamps, no offset), cveTags[], descriptions[{lang, text}], descriptionCount, cvss {v40[], v31[], v30[]} (each {source, type: Primary|Secondary, version, vectorString, baseScore, baseSeverity, exploitabilityScore, impactScore}), weaknesses[{source, type, cweIds[]}], references[{url, source, tags[]}], referenceCount, referencesDelivered, kev}. kev is {status: LISTED|NOT_LISTED, dateAdded, dueDate, knownRansomwareCampaignUse: KNOWN|UNKNOWN|null, vendorProject, product, vulnerabilityName, cwes[], catalogVersion, catalogDateReleased}. Text fields (text, url, names) are {status: OK, value} or {status: WITHHELD_UNSAFE_TEXT|WITHHELD_NOT_VERBATIM, rawSha256}: never altered. NOT_FOUND carries cveId, nvdUrl and kev.","type":"object"},"source":{"description":"Attribution: {publisher, publishers[], endpoints[], retrievedAt, rightsBasis: US_FEDERAL_PUBLIC_RECORD_SELF_OBSERVED, endorsement: NONE, notices[]}. notices are NVD's required notice, the CVE Program terms of use with MITRE's copyright designation, FIRST's CVSS attribution, CISA's KEV licence and Arbiter's verbatim rule.","type":"object"},"subject":{"description":"What was looked up: {kind: CVE, cveId}.","type":"object"},"uncertainty":{"description":"Plain-language limits of this record.","type":"string"}},"required":["program","subject","record","source","citations","observedAt","uncertainty"],"type":"object","x-arbiter-contentType":"application/json","x-arbiter-schemaVersion":"1.0.0"},"payment":{"admitted":true,"challengeHeader":"PAYMENT-REQUIRED","destination":{"address":"0x63aA5960943865e7d57FDdF0D899eE36B6D2046E","assetContracts":["0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48","0x0b2C639c533813f4Aa9D7837CAf62653d097Ff85","0xe15fC38F6D8c56aF07bbCBe3BAf5708A2Bf42392","0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359","0x754704Bc059F8C67012fEd69BC8A327a5aafb603","0xaf88d065e77c8cC2239327C5EDb3A432268e5831","0xB97EF9Ef8734C71904D8002F8b6Bc66Dd9c48a6E","0x3600000000000000000000000000000000000000","0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"],"bindingVersion":"a2f250e514c4a05c34efc98c49a4f4ac01a67770884883d19ff3a6487972ed90","networks":["eip155:1","eip155:10","eip155:1329","eip155:137","eip155:143","eip155:42161","eip155:43114","eip155:5042","eip155:8453"],"resolvable":true,"source":"x402_seller_configuration.payTo"},"logicalPaymentHeader":"ARBITER-LOGICAL-PAYMENT-ID","payToSource":"the canonical RevenueWalletResolver binding (x402_seller_configuration.payTo); never an environment value and never a literal","paymentIdentifier":{"extension":"payment-identifier","semantics":"Retries carrying the same payment identifier return the cached delivery with the same receipt: no second settlement, no second work, no second delivery credit.","supported":true},"processingSemantics":"A 202 means verification or settlement is still in progress; retry the same call with the same payment and the same payment identifier.","protocol":"X402_V2","protocolVersion":2,"quoteHeader":"ARBITER-QUOTE-ID","scheme":"exact","signatureHeader":"PAYMENT-SIGNATURE"},"pricing":{"currency":"USD","floorUsd":0.004,"mode":"DYNAMIC_QUOTE","ownerCeilingUsd":null,"pricingClass":"CACHEABLE_UNIT","publicStartingPriceUsd":0.004},"productId":"VULNERABILITY_RECORD_LOOKUP","productVersion":"1.0.0","provenance":{"basis":"PUBLIC_RECORD","protocols":[],"sources":["NIST National Vulnerability Database (CVE Program)"]},"resourceUrl":"https://arbiterverse.com/api/x402/VULNERABILITY_RECORD_LOOKUP","schemaVersion":"1.0.0","summary":"One CVE's official record from the NIST National Vulnerability Database, with its CISA Known Exploited Vulnerabilities status. This product uses the NVD API but is not endorsed or certified by the NVD. Includes descriptions, CVSS v4.0 and v3.1 scores with vectors, CWE ids, references, NVD status and dates, and the KEV date added, due date and known ransomware use. Read after payment and cited to Arbiter's archived copy. Example request: {\"cveId\":\"CVE-2021-44228\"}.","title":"Vulnerability record lookup (CVE)"}