The vulnerabilities this host is affected by that **nothing fixes in its release** (DAWG-212 part 2): no advisory will ever name them, so neither the update list nor [`exposures`] can. Debian only, from the security tracker; worst first, then longest standing.
GET
/v1/orgs/{org}/hosts/{host_id}/unfixed
const url = 'https://api.updawg.net/v1/orgs/example/hosts/example/unfixed';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.updawg.net/v1/orgs/example/hosts/example/unfixedParameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”org
required
string
Organization slug.
host_id
required
string
The hst_… id.
Responses
Section titled “Responses”Every unfixed vulnerability affecting the host. Empty for a host that has none — or whose agent is too old to report source packages, or that is not Debian.
Media typeapplication/json
object
unfixed
required
Array<object>
object
binary
required
boolean
description
required
string
first_seen_at
required
string format: date-time
fixed_upstream
The version that fixes it in Debian unstable. Absent: fixed nowhere.
string | null
installed
required
Its version on the host.
string
package
required
The source package the security tracker names — or, when binary, a
binary one.
string
remote
Remotely exploitable. Absent: not known.
boolean | null
urgency
low, medium or high. ⚠️ Absent means nobody rated it, not that
it is harmless.
string | null
vulnerability
required
CVE-…, or the tracker’s TEMP-… for one without a CVE yet.
string
Examplegenerated
{ "unfixed": [ { "binary": true, "description": "example", "first_seen_at": "2026-04-15T12:00:00Z", "fixed_upstream": "example", "installed": "example", "package": "example", "remote": true, "urgency": "example", "vulnerability": "example" } ]}No session.
Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Not permitted.
Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No such host, or not yours.
Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.
Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}