Skip to content

`GET /v1/orgs/{org}/hosts/{host_id}/exposures` (DAWG-212).

GET
/v1/orgs/{org}/hosts/{host_id}/exposures
curl --request GET \
--url https://api.updawg.net/v1/orgs/example/hosts/example/exposures

The advisories this host’s installed packages are affected by, whether or not an update fixes them. Unfixable first: those are the ones nothing in the update list will ever show.

org
required
string

Organization slug.

host_id
required
string

The hst_… id.

Every exposure, unfixable first, then worst first. Empty for a host that is up to date — or one not evaluated since exposures existed.

Media typeapplication/json
object
exposures
required
Array<object>
object
advisory
required
object
cves
required
Array<string>
external_id
required

USN-7012-1, DSA-6335-1, RLSA-2026:67165, …

string
id
required
string
source
required
string
title
required
string
url
string | null
first_seen_at
required

When this installed version was first seen exposed.

string format: date-time
fixable
required

Whether an update available to this host reaches fixed_version. false is the urgent case: affected, and nothing to install.

boolean
fixed_version
required

The version the advisory says fixes it.

string
installed
required
string
package
required
string
severity

Normalised, from the vendor’s rating or else the worst CVSS. null means nobody rated it, which is not the same as harmless.

string | null
unfixable
required

How many of exposures no available update fixes.

integer
Examplegenerated
{
"exposures": [
{
"advisory": {
"cves": [
"example"
],
"external_id": "example",
"id": "example",
"source": "example",
"title": "example",
"url": "example"
},
"first_seen_at": "2026-04-15T12:00:00Z",
"fixable": true,
"fixed_version": "example",
"installed": "example",
"package": "example",
"severity": "example"
}
],
"unfixable": 1
}

No session.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Not permitted.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

No such host, or not yours.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}