{"uid":"cap_79V90jH7Rq-OeEvDCF6W_","slug":"cyclonedx-sbom-vulnerability-check-osv-cisa-kev-c290c9c2","name":"CycloneDX SBOM Vulnerability Check (OSV + CISA KEV)","description":"CycloneDX SBOM vulnerability check — analyze bounded JSON 1.5 software bill of materials components against OSV and prioritize exact CVE matches from CISA KEV without remote document fetches.","url":"https://dependency-risk.use.x402atlas.com/sbom","method":"POST","headers":{},"bodySchema":null,"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_bUrXa0bIlG1x8ToKA699L","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes a CycloneDX 1.5 JSON Software Bill of Materials against OSV vulnerability data and prioritizes exact CVE matches from the CISA Known Exploited Vulnerabilities catalog.","exampleAgentPrompt":"Can you scan this CycloneDX 1.5 SBOM JSON for vulnerabilities — check it against OSV and flag any components that match CISA KEV entries as highest priority?","exampleUseCases":[{"title":"Pre-release security gate for software","prompt":"Before we ship this release, run our CycloneDX SBOM through the vulnerability checker and tell me if any components are in the CISA Known Exploited Vulnerabilities list — those need to be fixed before we can release."},{"title":"CI/CD pipeline vulnerability audit","prompt":"I've got a CycloneDX 1.5 JSON SBOM generated from our build — check every component against OSV and highlight any CVEs, especially ones flagged by CISA KEV so we know what's actively being exploited in the wild."},{"title":"Third-party vendor SBOM risk assessment","prompt":"A vendor just sent us their software bill of materials in CycloneDX 1.5 JSON format — can you check it for known vulnerabilities using OSV and tell me which CVEs are in the CISA KEV catalog so I can prioritize my risk assessment?"}],"resultDescription":"Returns a list of vulnerable components found in the SBOM, matched against OSV vulnerability records, with exact CVE identifiers and special prioritization flags for entries appearing in the CISA Known Exploited Vulnerabilities (KEV) catalog. Each finding includes the affected component, version, CVE ID, and severity or exploitability signals.","failureModes":["Malformed or non-CycloneDX-1.5 JSON input returns a validation error","SBOM too large or exceeding bounded component limits returns a size/payload error","Unknown or ambiguous package identifiers that cannot be matched in OSV return no findings for those components","Network or OSV lookup failures may result in partial results or error responses","Invalid purl formats in SBOM components may cause those entries to be skipped"],"whenToPreferThis":"Choose this endpoint when you have a full CycloneDX 1.5 JSON SBOM and need a comprehensive vulnerability sweep across all components in a single call, with CISA KEV prioritization to focus remediation on actively exploited CVEs. Prefer this over the single-package endpoint when scanning entire projects or vendor-supplied BOMs. Prefer over the batch dependency endpoint when your input is already in CycloneDX SBOM format rather than a plain package list.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:35:44.980Z","isFirstParty":false}