Skip to content
Start here

Get reviewed vulnerability report

managed_defense.vulnerability_discovery.reports.get(strscan_id, ReportGetParams**kwargs) -> ReportGetResponse
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos/{repo_id}/scans/{scan_id}/report

Gets the repository projection of the active operator-reviewed scan report. scan_id is the customer scan’s stable request ID.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
ParametersExpand Collapse
account_id: str
repo_id: str
formatuuid
scan_id: str
formatuuid
ReturnsExpand Collapse
class ReportGetResponse: …
publication: Publication
published_at: datetime
formatdate-time
revision_id: str
formatuuid
version: int
minimum1
report: Report
findings: List[ReportFinding]
id: str
maxLength128
minLength1
conditions: List[str]
cwe: str
minLength1
impact: str
maxLength4000
minLength1
location: ReportFindingLocation
file: str
minLength1
line: int
minimum1
route: Optional[str]
reachability: List[ReportFindingReachability]
consumer: str
minLength1
reachable: bool
via: str
remediation: ReportFindingRemediation
code_changes: Optional[str]
strategy: str
minLength1
root_cause: str
maxLength4000
minLength1
severity: Literal["critical", "high", "medium", 2 more]
One of the following:
"critical"
"high"
"medium"
"low"
"info"
severity_basis: str
minLength1
summary: str
maxLength4000
minLength1
telemetry: ReportFindingTelemetry
references: List[str]
state: Literal["no_route", "no_telemetry", "no_match", "matched"]
One of the following:
"no_route"
"no_telemetry"
"no_match"
"matched"
title: str
maxLength200
minLength1
trace: List[ReportFindingTrace]
line: int
minimum1
path: str
minLength1
scope: str
why: str
waf_rules: Optional[ReportFindingWAFRules]
broad: Optional[ReportFindingWAFRulesBroad]
action: Literal["block", "managed_challenge", "js_challenge", "log"]
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: Literal["low", "medium", "high"]
One of the following:
"low"
"medium"
"high"
description: str
minLength1
expression: str
maxLength4096
minLength1
false_positive_risk: str
minLength1
name: str
maxLength25
minLength1
rationale: str
minLength1
targeted: Optional[ReportFindingWAFRulesTargeted]
action: Literal["block", "managed_challenge", "js_challenge", "log"]
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: Literal["low", "medium", "high"]
One of the following:
"low"
"medium"
"high"
description: str
minLength1
expression: str
maxLength4096
minLength1
false_positive_risk: str
minLength1
name: str
maxLength25
minLength1
rationale: str
minLength1
attacker_position: Optional[Literal["external", "authenticated", "internal", "post_compromise"]]

Least-privileged position required to trigger the finding. Optional on legacy report revisions.

One of the following:
"external"
"authenticated"
"internal"
"post_compromise"
open_question: Optional[str]

One bounded unresolved proof question. Optional on legacy report revisions.

maxLength500
proof_method: Optional[Literal["structural", "experimental", "acquired_source", 2 more]]

Method used or needed to close the proof. Optional on legacy report revisions.

One of the following:
"structural"
"experimental"
"acquired_source"
"public_knowledge"
"team_question"
proof_state: Optional[Literal["closed", "pending_source", "pending_public", 2 more]]

Current proof lifecycle state. Optional on legacy report revisions.

One of the following:
"closed"
"pending_source"
"pending_public"
"pending_experiment"
"pending_team"
overall_severity: Literal["critical", "high", "medium", 2 more]
One of the following:
"critical"
"high"
"medium"
"low"
"info"
repository_id: str
formatuuid
repository_name: str
minLength1
summary: str
maxLength4000
minLength1
traffic_context: ReportTrafficContext
http: Optional[ReportTrafficContextHTTP]
error_paths: List[ReportTrafficContextHTTPErrorPath]
id: str
minLength1
hits: float
minimum0
host: str
minLength1
path: str
minLength1
status: int
maximum599
minimum100
hot_paths: List[ReportTrafficContextHTTPHotPath]
id: str
minLength1
hits: float
minimum0
host: str
minLength1
path: str
minLength1
top_status: int
maximum599
minimum100
request_volume: float
minimum0
target: Optional[ReportTrafficContextTarget]
hosts: List[str]
kind: Literal["worker", "origin"]
One of the following:
"worker"
"origin"
telemetry_window: Optional[ReportTrafficContextTargetTelemetryWindow]

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: datetime
formatdate-time
start: datetime
formatdate-time
waf: Optional[ReportTrafficContextWAF]
hit_volume: float
minimum0
rules: List[ReportTrafficContextWAFRule]
id: str
minLength1
hit_volume: float
minimum0
paths: List[ReportTrafficContextWAFRulePath]
id: str
minLength1
hit_volume: float
minimum0
host: str
minLength1
path: str
minLength1
rule_id: str
minLength1
rule_version: Optional[int]
minimum0
web_assets: Optional[ReportTrafficContextWebAssets]
operations: List[ReportTrafficContextWebAssetsOperation]
id: str
minLength1
endpoint: str
minLength1
host: str
minLength1
method: str
minLength1
risk_labels: List[ReportTrafficContextWebAssetsOperationRiskLabel]
description: Optional[str]
name: str
minLength1
performance: Optional[ReportTrafficContextWebAssetsOperationPerformance]
avg_origin_latency_ms: Optional[float]
minimum0
error_rate: float
maximum1
minimum0
estimated_requests: float
minimum0
paths: List[ReportTrafficContextWebAssetsPath]
id: str
minLength1
avg_origin_latency_ms: Optional[float]
minimum0
error_rate: float
maximum1
minimum0
estimated_requests: float
minimum0
host: str
minLength1
path: str
minLength1
risk_types: List[ReportTrafficContextWebAssetsRiskType]
description: Optional[str]
name: str
minLength1
operation_count: int
minimum0
limitations: Optional[List[str]]
repository_id: str
formatuuid
scan_id: str
maxLength128
minLength1

Get reviewed vulnerability report

import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_token=os.environ.get("CLOUDFLARE_API_TOKEN"),  # This is the default and can be omitted
)
report = client.managed_defense.vulnerability_discovery.reports.get(
    scan_id="182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    account_id="023e105f4ecef8ad9ca31a8372d0c353",
    repo_id="182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
)
print(report.repository_id)
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "publication": {
      "published_at": "2019-12-27T18:11:19.117Z",
      "revision_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "version": 1
    },
    "report": {
      "findings": [
        {
          "id": "x",
          "conditions": [
            "string"
          ],
          "cwe": "x",
          "impact": "x",
          "location": {
            "file": "x",
            "line": 1,
            "route": "route"
          },
          "reachability": [
            {
              "consumer": "x",
              "reachable": true,
              "via": "via"
            }
          ],
          "remediation": {
            "code_changes": "code_changes",
            "strategy": "x"
          },
          "root_cause": "x",
          "severity": "critical",
          "severity_basis": "x",
          "summary": "x",
          "telemetry": {
            "references": [
              "x"
            ],
            "state": "no_route"
          },
          "title": "x",
          "trace": [
            {
              "line": 1,
              "path": "x",
              "scope": "scope",
              "why": "why"
            }
          ],
          "waf_rules": {
            "broad": {
              "action": "block",
              "confidence": "low",
              "description": "x",
              "expression": "x",
              "false_positive_risk": "x",
              "name": "x",
              "rationale": "x"
            },
            "targeted": {
              "action": "block",
              "confidence": "low",
              "description": "x",
              "expression": "x",
              "false_positive_risk": "x",
              "name": "x",
              "rationale": "x"
            }
          },
          "attacker_position": "external",
          "external_links": [
            {
              "title": "x",
              "url": "https://example.com"
            }
          ],
          "open_question": "open_question",
          "proof_method": "structural",
          "proof_state": "closed"
        }
      ],
      "overall_severity": "critical",
      "repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "repository_name": "x",
      "summary": "x",
      "traffic_context": {
        "http": {
          "error_paths": [
            {
              "id": "x",
              "hits": 0,
              "host": "x",
              "path": "x",
              "status": 100
            }
          ],
          "hot_paths": [
            {
              "id": "x",
              "hits": 0,
              "host": "x",
              "path": "x",
              "top_status": 100
            }
          ],
          "request_volume": 0
        },
        "target": {
          "hosts": [
            "x"
          ],
          "kind": "worker",
          "telemetry_window": {
            "end": "2019-12-27T18:11:19.117Z",
            "start": "2019-12-27T18:11:19.117Z"
          }
        },
        "waf": {
          "hit_volume": 0,
          "rules": [
            {
              "id": "x",
              "hit_volume": 0,
              "paths": [
                {
                  "id": "x",
                  "hit_volume": 0,
                  "host": "x",
                  "path": "x"
                }
              ],
              "rule_id": "x",
              "rule_version": 0
            }
          ]
        },
        "web_assets": {
          "operations": [
            {
              "id": "x",
              "endpoint": "x",
              "host": "x",
              "method": "x",
              "risk_labels": [
                {
                  "description": "description",
                  "name": "x"
                }
              ],
              "performance": {
                "avg_origin_latency_ms": 0,
                "error_rate": 0,
                "estimated_requests": 0
              }
            }
          ],
          "paths": [
            {
              "id": "x",
              "avg_origin_latency_ms": 0,
              "error_rate": 0,
              "estimated_requests": 0,
              "host": "x",
              "path": "x"
            }
          ],
          "risk_types": [
            {
              "description": "description",
              "name": "x",
              "operation_count": 0
            }
          ]
        }
      },
      "external_links": [
        {
          "title": "x",
          "url": "https://example.com"
        }
      ],
      "limitations": [
        "x"
      ]
    },
    "repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "scan_id": "x"
  },
  "success": true
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "publication": {
      "published_at": "2019-12-27T18:11:19.117Z",
      "revision_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "version": 1
    },
    "report": {
      "findings": [
        {
          "id": "x",
          "conditions": [
            "string"
          ],
          "cwe": "x",
          "impact": "x",
          "location": {
            "file": "x",
            "line": 1,
            "route": "route"
          },
          "reachability": [
            {
              "consumer": "x",
              "reachable": true,
              "via": "via"
            }
          ],
          "remediation": {
            "code_changes": "code_changes",
            "strategy": "x"
          },
          "root_cause": "x",
          "severity": "critical",
          "severity_basis": "x",
          "summary": "x",
          "telemetry": {
            "references": [
              "x"
            ],
            "state": "no_route"
          },
          "title": "x",
          "trace": [
            {
              "line": 1,
              "path": "x",
              "scope": "scope",
              "why": "why"
            }
          ],
          "waf_rules": {
            "broad": {
              "action": "block",
              "confidence": "low",
              "description": "x",
              "expression": "x",
              "false_positive_risk": "x",
              "name": "x",
              "rationale": "x"
            },
            "targeted": {
              "action": "block",
              "confidence": "low",
              "description": "x",
              "expression": "x",
              "false_positive_risk": "x",
              "name": "x",
              "rationale": "x"
            }
          },
          "attacker_position": "external",
          "external_links": [
            {
              "title": "x",
              "url": "https://example.com"
            }
          ],
          "open_question": "open_question",
          "proof_method": "structural",
          "proof_state": "closed"
        }
      ],
      "overall_severity": "critical",
      "repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "repository_name": "x",
      "summary": "x",
      "traffic_context": {
        "http": {
          "error_paths": [
            {
              "id": "x",
              "hits": 0,
              "host": "x",
              "path": "x",
              "status": 100
            }
          ],
          "hot_paths": [
            {
              "id": "x",
              "hits": 0,
              "host": "x",
              "path": "x",
              "top_status": 100
            }
          ],
          "request_volume": 0
        },
        "target": {
          "hosts": [
            "x"
          ],
          "kind": "worker",
          "telemetry_window": {
            "end": "2019-12-27T18:11:19.117Z",
            "start": "2019-12-27T18:11:19.117Z"
          }
        },
        "waf": {
          "hit_volume": 0,
          "rules": [
            {
              "id": "x",
              "hit_volume": 0,
              "paths": [
                {
                  "id": "x",
                  "hit_volume": 0,
                  "host": "x",
                  "path": "x"
                }
              ],
              "rule_id": "x",
              "rule_version": 0
            }
          ]
        },
        "web_assets": {
          "operations": [
            {
              "id": "x",
              "endpoint": "x",
              "host": "x",
              "method": "x",
              "risk_labels": [
                {
                  "description": "description",
                  "name": "x"
                }
              ],
              "performance": {
                "avg_origin_latency_ms": 0,
                "error_rate": 0,
                "estimated_requests": 0
              }
            }
          ],
          "paths": [
            {
              "id": "x",
              "avg_origin_latency_ms": 0,
              "error_rate": 0,
              "estimated_requests": 0,
              "host": "x",
              "path": "x"
            }
          ],
          "risk_types": [
            {
              "description": "description",
              "name": "x",
              "operation_count": 0
            }
          ]
        }
      },
      "external_links": [
        {
          "title": "x",
          "url": "https://example.com"
        }
      ],
      "limitations": [
        "x"
      ]
    },
    "repository_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "scan_id": "x"
  },
  "success": true
}