`GET /v1/orgs/{org}/hosts/{host_id}/exposures` (DAWG-212).
const url = 'https://api.updawg.net/v1/orgs/example/hosts/example/exposures';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.updawg.net/v1/orgs/example/hosts/example/exposuresThe advisories this host’s installed packages are affected by, whether or not an update fixes them. Unfixable first: those are the ones nothing in the update list will ever show.
Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Organization slug.
The hst_… id.
Responses
Section titled “Responses”Every exposure, unfixable first, then worst first. Empty for a host that is up to date — or one not evaluated since exposures existed.
object
object
object
USN-7012-1, DSA-6335-1, RLSA-2026:67165, …
When this installed version was first seen exposed.
Whether an update available to this host reaches fixed_version.
false is the urgent case: affected, and nothing to install.
The version the advisory says fixes it.
Normalised, from the vendor’s rating or else the worst CVSS. null
means nobody rated it, which is not the same as harmless.
How many of exposures no available update fixes.
Examplegenerated
{ "exposures": [ { "advisory": { "cves": [ "example" ], "external_id": "example", "id": "example", "source": "example", "title": "example", "url": "example" }, "first_seen_at": "2026-04-15T12:00:00Z", "fixable": true, "fixed_version": "example", "installed": "example", "package": "example", "severity": "example" } ], "unfixable": 1}No session.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Not permitted.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No such host, or not yours.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}