All Products
Search
Document Center

Security Center:DescribeImageVulList

Last Updated:Sep 17, 2026

Queries the details of vulnerabilities detected by image security scans and the list of container images affected by the vulnerabilities.

Operation description

To view the latest container image vulnerability information, call the PublicCreateImageScanTask operation to create an image scan task first. Wait 1 to 5 minutes, and then call this operation to query the container image vulnerability list.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeImageVulList

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

Lang

string

No

The language type of the request and response. Default value: zh. Valid values:

  • zh: Chinese

  • en: English

zh

Type

string

Yes

The type of the vulnerability to query. Set the value to cve, which indicates container image vulnerabilities.

cve

Uuids

string

No

The UUIDs of the asset instances. Separate multiple UUIDs with commas (,).

0004a32a0305a7f6ab5ff9600d47****

Name

string

No

The name of the vulnerability to query.

debian:10:CVE-2019-9893

AliasName

string

No

The alias of the vulnerability to query.

High severity vulnerability that affects org.eclipse.jetty:jetty-server

StatusList

string

No

The fix status of the vulnerability. Valid values:

  • 1: Unfixed.

  • 4: Being fixed.

  • 7: Fixed.

1

Necessity

string

No

The priority of vulnerability fixing. Valid values:

  • asap: high-priority vulnerability

  • later: medium-priority vulnerability

  • nntf: low-priority vulnerability

asap

Dealed

string

No

Specifies whether the vulnerability has been handled. Valid values:

  • y: Handled.

  • n: Not handled.

y

CurrentPage

integer

No

The page number of the page to return in the query results. Default value: 1, which indicates that the first page is returned.

1

PageSize

integer

No

Settings for paged query. The number of vulnerabilities to display on each page during paging. Default value: 10, which indicates that 10 vulnerabilities are displayed on each page.

10

RepoRegionId

string

No

The region ID of the container image repository.

cn-hangzhou

RepoInstanceId

string

No

The instance ID of the container image repository.

i-qewqrqcsadf****

RepoId

string

No

The ID of the container image repository.

qew****

RepoName

string

No

The name of the container image repository.

libssh2

RepoNamespace

string

No

The namespace of the container image repository.

libssh2

RegionId

string

No

The region ID of the instance.

cn-hangzhou

InstanceId

string

No

The ID of the asset instance.

1-qeqewqw****

Tag

string

No

The tag of the container image.

oval

Digest

string

No

The unique identifier of the container image.

8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d507012

ClusterId

string

No

The ID of the container cluster.

cc20a1024011c44b6a8710d6f8b****

ScanRange

array

No

The collection of scan ranges.

string

No

The scan range. Valid values:

  • container: container

  • image: image

container

ClusterName

string

No

The cluster name.

docker-law

ContainerId

string

No

The container ID.

c08d5fc1a329a4b88950a253d082f****

Pod

string

No

The pod.

22222-7xsqq

Namespace

string

No

The namespace.

test-002

Image

string

No

The container image name.

registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-****

RuleTag

string

No

The vulnerability tag. Valid values:

  • AI: vulnerabilities related to AI components

AI

GroupByAsset

boolean

No

Specifies whether to group results by image asset before pagination. If set to true, one vulnerability record is returned for each asset, and TotalCount indicates the total number of assets. If set to false or not specified, results are paginated by vulnerability record. Asset grouping is not applied when MaxId is specified.

ResourceDirectoryAccountId

integer

No

The ID of the Alibaba Cloud account that is added as one of the member accounts in a resource folder.

Note

Invoke the DescribeMonitorAccounts operation to obtain this parameter.

127608589417****

Response elements

Element

Type

Description

Example

object

CurrentPage

integer

The page number of the current page when paging is used.

1

PageSize

integer

The number of vulnerabilities displayed per page when paging is used. Default value: 10, which indicates that 10 vulnerabilities are displayed per page.

10

RequestId

string

The ID of the request. Alibaba Cloud generates a unique identifier for each request. You can use the ID to troubleshoot issues.

D6B20156-49B0-5CF0-B14D-7ECA4B50DAAB

TotalCount

integer

The total number of vulnerabilities returned by the query.

1

VulRecords

array<object>

The list of vulnerability information.

array<object>

The vulnerability information.

AgentlessCanFix

boolean

Indicates whether the vulnerability supports agentless remediation. true: supported. false: not supported. If this field is not returned, no corresponding remediation capability information is available.

AliasName

string

The alias of the vulnerability.

CVE-2018-25010:libwebp up to 1.0.0 ApplyFilter out-of-bounds read

CanFix

string

Indicates whether the vulnerability can be fixed from the console. Valid values:

  • yes: Can be fixed.

  • no: Cannot be fixed.

yes

CanUpdate

boolean

Indicates whether the software package that causes the vulnerability can be upgraded through Security Center. Valid values:

  • true: Upgrade is supported.

  • false: Upgrade is not supported.

true

ClusterId

string

The cluster ID.

c08d5fc1a329a4b88950a253d082f1****

ClusterName

string

The cluster name.

docker-law

ContainerId

string

The container ID.

04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163****

ExtendContentJson

object

The extended content of the vulnerability information.

Os

string

The name of the operating system.

debian

OsRelease

string

The operating system release version corresponding to the container image.

10.9

RpmEntityList

array<object>

The list of software packages that cause the vulnerability.

object

The information about the software package that causes the vulnerability.

FullVersion

string

The full version number of the software package.

2.3.3-4

Layer

string

The SHA256 digest of the container image layer.

b1f5b9420803ad0657cf21566e3e20acc08581e7f22991249ef3aa80b8b1c587

MatchDetail

string

The details of the vulnerability match.

libseccomp2 version less than equals 2.3.3-4

MatchList

array

The list of matched rule details.

["libseccomp2 version less than equals 2.3.3-4"]

string

The details of matched rules. Details of multiple rules are separated by commas (,).

["libstdc++ version less than 8.5.0-4.el8_5"]

Name

string

The name of the software package.

libseccomp2

Path

string

The path of the vulnerable software.

/usr/lib64/libssh2.so.1

UpdateCmd

string

The command to fix the vulnerability.

apt-get update && apt-get install libseccomp2 --only-upgrade

Version

string

The version number of the software package.

2.3.3-4

FirstTs

integer

The timestamp of the first scan, in milliseconds.

1620752053000

Image

string

The image name.

registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-conta****

ImageDigest

string

The unique identifier of the container image.

8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d507012

InstanceName

string

The name of the asset instance.

testInstance

InternetIp

string

The public IP address of the server.

1.2.XX.XX

IntranetIp

string

The private IP address of the server.

172.19.XX.XX

LastTs

integer

The timestamp of the most recent scan, in milliseconds.

1631779996000

Layers

array

The list of container image layers.

string

The list of container image layers.

["null"]

MaliciousSource

string

The source of the malicious file. Valid values:

  • agentless: Agentless detection.

  • image: Image.

  • container: Container.

agentless

ModifyTs

integer

The timestamp when the vulnerability record was updated, in milliseconds.

1580808765000

Name

string

The name of the vulnerability.

debian:10:CVE-2019-9893

Namespace

string

The namespace.

test-002

Necessity

string

The priority of vulnerability fixing. Valid values:

  • asap: high-priority vulnerability

  • later: medium-priority vulnerability

  • nntf: low-priority vulnerability

asap

Pod

string

The pod.

22222-7xsqq

PrimaryId

integer

The ID of the vulnerability.

782661

Related

string

The details of the associated vulnerability.

CVE-2019-9893

RepoName

string

The name of the container image repository.

varnish

RepoNamespace

string

The namespace of the container image repository.

default

RuleTag

string

The vulnerability tag. Valid values:

  • AI: Vulnerability related to AI components.

AI

ScanTime

integer

The timestamp of the scan, in milliseconds.

1649814050000

Status

integer

The fix status of the vulnerability. Valid values:

  • 1: Not fixed.

  • 7: Fixed.

1

Tag

string

The tag of the container image vulnerability.

oval

TargetId

string

The ID of the scan target.

m-bp17m0pc0xprzbwo****

TargetName

string

The name of the scan target.

source-test-obj-XM0Ma

TargetType

string

The object type of the scan target. Valid values:

  • ECS_IMAGE: Image.

  • ECS_SNAPSHOT: Snapshot.

ECS_IMAGE

Type

string

The type of the vulnerability queried. The value is fixed as cve, which indicates container image vulnerabilities.

cve

Uuid

string

The UUID of the server.

0004a32a0305a7f6ab5ff9600d47****

Examples

Success response

JSON format

{
  "CurrentPage": 1,
  "PageSize": 10,
  "RequestId": "D6B20156-49B0-5CF0-B14D-7ECA4B50DAAB",
  "TotalCount": 1,
  "VulRecords": [
    {
      "AgentlessCanFix": false,
      "AliasName": "CVE-2018-25010:libwebp up to 1.0.0 ApplyFilter out-of-bounds read",
      "CanFix": "yes",
      "CanUpdate": true,
      "ClusterId": "c08d5fc1a329a4b88950a253d082f1****\n",
      "ClusterName": "docker-law\n",
      "ContainerId": "04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163****\n",
      "ExtendContentJson": {
        "Os": "debian",
        "OsRelease": "10.9",
        "RpmEntityList": [
          {
            "FullVersion": "2.3.3-4",
            "Layer": "b1f5b9420803ad0657cf21566e3e20acc08581e7f22991249ef3aa80b8b1c587",
            "MatchDetail": "libseccomp2 version less than equals 2.3.3-4",
            "MatchList": [
              "[\"libstdc++ version less than 8.5.0-4.el8_5\"]"
            ],
            "Name": "libseccomp2",
            "Path": "/usr/lib64/libssh2.so.1",
            "UpdateCmd": "apt-get update && apt-get install libseccomp2  --only-upgrade",
            "Version": "2.3.3-4"
          }
        ]
      },
      "FirstTs": 1620752053000,
      "Image": "registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-conta****\n",
      "ImageDigest": "8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d507012",
      "InstanceName": "testInstance",
      "InternetIp": "1.2.XX.XX",
      "IntranetIp": "172.19.XX.XX",
      "LastTs": 1631779996000,
      "Layers": [
        "[\"null\"]"
      ],
      "MaliciousSource": "agentless",
      "ModifyTs": 1580808765000,
      "Name": "debian:10:CVE-2019-9893",
      "Namespace": "test-002\n",
      "Necessity": "asap",
      "Pod": "22222-7xsqq\n",
      "PrimaryId": 782661,
      "Related": "CVE-2019-9893",
      "RepoName": "varnish",
      "RepoNamespace": "default",
      "RuleTag": "AI",
      "ScanTime": 1649814050000,
      "Status": 1,
      "Tag": "oval",
      "TargetId": "m-bp17m0pc0xprzbwo****",
      "TargetName": "source-test-obj-XM0Ma",
      "TargetType": "ECS_IMAGE",
      "Type": "cve",
      "Uuid": "0004a32a0305a7f6ab5ff9600d47****"
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 RdCheckNoPermission Resource directory account verification has no permission.
500 ServerError ServerError
500 RdCheckInnerError Resource directory account service internal error.
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.