---
title: "List Catalog Vulnerability-Services"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/operations/list-catalog-vulnerability-services"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# List Catalog Vulnerability-Services

`GET` `/vulnerability-catalog-services`

Operation ID: `list-catalog-vulnerability-services`

Returns a paginated collection of services with cross-vulnerability context.

## Query parameters

- `page[size]` (integer, optional) - The maximum number of items to include per page. The last page of a collection may include fewer items.
- `page[number]` (integer, optional) - Determines which page of the entities to retrieve.
- `sort` (string, optional) - Sorts a collection of services with cross-ulnerability context. Supported sort attributes are: - name - display_name - vulnerability.most_recent_vulnerability_opened_at - vulnerability.vulnerability_count - vulnerability.instance_count
- `filter` (object, optional) - Filters a collection of services with cross-vulnerability context.

## Responses

- `200` - A paginated list response for a collection of services with cross-vulnerability context.
- `400` - Bad Request
- `401` - Unauthorized
- `403` - Forbidden

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
paths:
  /vulnerability-catalog-services:
    get:
      x-unstable: true
      x-internal: true
      summary: List Catalog Vulnerability-Services
      operationId: list-catalog-vulnerability-services
      description: Returns a paginated collection of services with cross-vulnerability
        context.
      parameters:
        - $ref: "#/components/parameters/PageSize"
        - $ref: "#/components/parameters/PageNumber"
        - $ref: "#/components/parameters/CatalogVulnerabilityServiceSort"
        - $ref: "#/components/parameters/CatalogVulnerabilityServiceFilter"
      responses:
        "200":
          $ref: "#/components/responses/ListCatalogVulnerabilityServicesResponse"
        "400":
          $ref: "#/components/responses/BadRequest"
        "401":
          $ref: "#/components/responses/Unauthorized"
        "403":
          $ref: "#/components/responses/Forbidden"
      tags:
        - Vulnerabilities
security:
  - konnectAccessToken: []
  - personalAccessToken: []
  - systemAccountAccessToken: []
components:
  parameters:
    PageSize:
      name: page[size]
      description: The maximum number of items to include per page. The last page of a
        collection may include fewer items.
      required: false
      in: query
      allowEmptyValue: true
      schema:
        type: integer
        example: 10
    PageNumber:
      name: page[number]
      description: Determines which page of the entities to retrieve.
      required: false
      in: query
      allowEmptyValue: true
      schema:
        type: integer
        example: 1
    CatalogVulnerabilityServiceSort:
      name: sort
      description: >
        Sorts a collection of services with cross-ulnerability context.
        Supported sort attributes are:
          - name
          - display_name
          - vulnerability.most_recent_vulnerability_opened_at
          - vulnerability.vulnerability_count
          - vulnerability.instance_count
      required: false
      in: query
      schema:
        $ref: "#/components/schemas/SortQuery"
    CatalogVulnerabilityServiceFilter:
      name: filter
      description: Filters a collection of services with cross-vulnerability context.
      required: false
      in: query
      style: deepObject
      schema:
        $ref: "#/components/schemas/CatalogVulnerabilityServiceFilterParameters"
  responses:
    ListCatalogVulnerabilityServicesResponse:
      description: >
        A paginated list response for a collection of services with
        cross-vulnerability context.
      content:
        application/json:
          schema:
            type: object
            additionalProperties: false
            properties:
              meta:
                $ref: "#/components/schemas/PaginatedMeta"
              data:
                type: array
                items:
                  $ref: "#/components/schemas/CatalogVulnerabilityService"
            required:
              - meta
              - data
    BadRequest:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/BadRequestError"
    Unauthorized:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/UnauthorizedExample"
    Forbidden:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/ForbiddenExample"
  schemas:
    SortQuery:
      title: SortQuery
      type: string
      example: created_at desc
      description: >
        The `asc` suffix is optional as the default sort order is ascending.

        The `desc` suffix is used to specify a descending order.

        Multiple sort attributes may be provided via a comma separated list.

        JSONPath notation may be used to specify a sub-attribute (eg: 'foo.bar
        desc').
    CatalogVulnerabilityServiceFilterParameters:
      title: CatalogVulnerabilityServiceFilterParameters
      type: object
      allOf:
        - type: object
          properties:
            name:
              $ref: "#/components/schemas/StringFieldFilter"
            display_name:
              $ref: "#/components/schemas/StringFieldFilter"
            labels:
              $ref: "#/components/schemas/LabelsFieldFilter"
            vulnerability.most_recent_vulnerability_opened_at:
              $ref: "#/components/schemas/DateTimeFieldFilter"
            vulnerability.instance_count:
              $ref: "#/components/schemas/NumericFieldFilter"
            vulnerability.vulnerability_count:
              $ref: "#/components/schemas/NumericFieldFilter"
            custom_fields:
              description: >
                Filter by custom fields using dot-notation to specify the custom
                field.

                Filter operators are dictated by the custom field type. For
                example:
                  - `filter[custom_fields.owner]`
                  - `filter[custom_fields.owner][neq]=kong`
                  - `filter[custom_fields.dashboard.link][contains]=https`
              oneOf:
                - $ref: "#/components/schemas/StringFieldFilter"
                - $ref: "#/components/schemas/BooleanFieldFilter"
                - $ref: "#/components/schemas/NumericFieldFilter"
    PaginatedMeta:
      type: object
      title: PaginatedMeta
      x-speakeasy-terraform-ignore: true
      description: returns the pagination information
      properties:
        page:
          $ref: "#/components/schemas/PageMeta"
      required:
        - page
    CatalogVulnerabilityService:
      title: CatalogVulnerabilityService
      description: Service representation that includes cross-vulnerability context.
      allOf:
        - $ref: "#/components/schemas/CatalogService"
        - type: object
          required:
            - vulnerability
          properties:
            vulnerability:
              $ref: "#/components/schemas/CatalogServiceVulnerabilityAttributes"
    BadRequestError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          required:
            - invalid_parameters
          properties:
            invalid_parameters:
              $ref: "#/components/schemas/InvalidParameters"
    UnauthorizedError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 401
            title:
              example: Unauthorized
            type:
              example: https://httpstatuses.com/401
            instance:
              example: kong:trace:1234567890
            detail:
              example: Invalid credentials
    ForbiddenError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 403
            title:
              example: Forbidden
            type:
              example: https://httpstatuses.com/403
            instance:
              example: kong:trace:1234567890
            detail:
              example: Forbidden
    StringFieldFilter:
      oneOf:
        - title: Filter by operator
          description: "Filter using **one** of the following operators: `eq`, `oeq`,
            `neq`, `contains`, `ocontains`"
          x-examples:
            example-1:
              contains: some-value
              ocontains: this-value,or-that-value
              oeq: some-value,some-other-value
              neq: not-this-value
            example-2:
              eq: some-value
          properties:
            eq:
              type: string
              description: The field exactly matches the provided value.
              example: ?filter[field_name_here][eq]=foo
            contains:
              type: string
              description: The field contains the provided value.
              example: ?filter[field_name_here][contains]=foo
            ocontains:
              type: string
              description: The field contains any of the provided values.
              example: ?filter[field_name_here][ocontains]=foo,bar
            oeq:
              type: string
              description: The field matches any of the provided values.
              example: ?filter[field_name_here][oeq]=foo,bar
            neq:
              type: string
              description: The field does not match the provided value.
              example: ?filter[field_name_here][neq]=bar
          type: object
          additionalProperties: false
        - title: Filter by exact string match
          type: string
          description: The field exactly matches the provided value.
          example: ?filter[title]=foo
    LabelsFieldFilter:
      allOf:
        - title: LabelsFieldFilter
          description: >
            Filters on the resource's `labels` field. Filters must use
            dot-notation to identify

            the label key that will be used to filter the results. For example:
              - `filter[labels.owner]`
              - `filter[labels.owner][neq]=kong`
              - `filter[labels.env]=dev`
              - `filter[labels.env][ocontains]=dev,test`
        - $ref: "#/components/schemas/StringFieldFilter"
    DateTimeFieldFilter:
      title: DateTimeFieldFilter
      description: Filters on the given datetime (RFC-3339) field value.
      oneOf:
        - type: string
          title: DateTimeFieldImplicitEqualsFilter
          format: date-time
          description: Value strictly equals given RFC-3339 formatted timestamp in UTC
          example: 2022-03-30T07:20:50Z
        - type: object
          title: DateTimeFieldEqualsFilter
          additionalProperties: false
          properties:
            eq:
              type: string
              format: date-time
              description: Value strictly equals given RFC-3339 formatted timestamp in UTC
              example: 2022-03-30T07:20:50Z
          required:
            - eq
        - type: object
          title: DateTimeFieldLTFilter
          additionalProperties: false
          properties:
            lt:
              type: string
              format: date-time
              description: Value is less than the given RFC-3339 formatted timestamp in UTC
              example: 2022-03-30T07:20:50Z
          required:
            - lt
        - type: object
          title: DateTimeFieldLTEFilter
          additionalProperties: false
          properties:
            lte:
              type: string
              format: date-time
              description: Value is less than or equal to the given RFC-3339 formatted
                timestamp in UTC
              example: 2022-03-30T07:20:50Z
          required:
            - lte
        - type: object
          title: DateTimeFieldGTFilter
          additionalProperties: false
          properties:
            lt:
              type: string
              format: date-time
              description: Value is greater than the given RFC-3339 formatted timestamp in UTC
              example: 2022-03-30T07:20:50Z
          required:
            - gt
        - type: object
          title: DateTimeFieldGTEFilter
          additionalProperties: false
          properties:
            lte:
              type: string
              format: date-time
              description: Value is greater than or equal to the given RFC-3339 formatted
                timestamp in UTC
              example: 2022-03-30T07:20:50Z
          required:
            - gte
      x-examples:
        datetime_field_1: 2022-03-30T07:20:50Z
        datetime_field_2:
          eq: 2022-03-30T07:20:50Z
        datetime_field_3:
          lt: 2022-03-30T07:20:50Z
        datetime_field_4:
          lte: 2022-03-30T07:20:50Z
        datetime_field_5:
          gt: 2022-03-30T07:20:50Z
        datetime_field_6:
          gte: 2022-03-30T07:20:50Z
    NumericFieldFilter:
      description: Filter by a numeric value.
      oneOf:
        - type: number
          description: Value strictly equals the given numeric value.
          example: 21
        - type: object
          title: NumericFieldEqualsFilter
          additionalProperties: false
          properties:
            eq:
              type: number
              description: Value strictly equals the given numeric value.
              example: 3.14
          required:
            - eq
        - type: object
          title: NumericFieldLTFilter
          additionalProperties: false
          properties:
            lt:
              type: number
              description: Value is less than the given numeric value.
              example: 10
          required:
            - lt
        - type: object
          title: NumericFieldLTEFilter
          additionalProperties: false
          properties:
            lte:
              type: number
              description: Value is less than or equal to the given numeric value.
              example: 10
          required:
            - lte
        - type: object
          title: NumericFieldGTFilter
          additionalProperties: false
          properties:
            gt:
              type: number
              description: Value is greater than the given numeric value.
              example: 1.85
          required:
            - gt
        - type: object
          title: NumericFieldGTEFilter
          additionalProperties: false
          properties:
            gte:
              type: number
              description: Value is greater than or equal to the given numeric value.
              example: 1.85
          required:
            - gte
      x-examples:
        numeric_field_1: 11
        numeric_field_2:
          eq: 11
        numeric_field_3:
          lt: 15.85
        numeric_field_4:
          lte: 15.85
        numeric_field_5:
          gt: 3.14
        numeric_field_6:
          gte: 3.14
    BooleanFieldFilter:
      title: BooleanFieldFilter
      description: Filter by a boolean value (true/false).
      type: boolean
      x-examples:
        example-1: true
    PageMeta:
      type: object
      description: Contains pagination query parameters and the total number of
        objects returned.
      required:
        - number
        - size
        - total
      properties:
        number:
          type: number
          example: 1
          x-speakeasy-terraform-ignore: true
        size:
          type: number
          example: 10
          x-speakeasy-terraform-ignore: true
        total:
          type: number
          example: 100
          x-speakeasy-terraform-ignore: true
    CatalogService:
      title: CatalogService
      description: The service object contains information about a Service Catalog service.
      type: object
      required:
        - id
        - name
        - display_name
        - description
        - custom_fields
        - labels
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
          example: 7f9fd312-a987-4628-b4c5-bb4f4fddd5f7
          description: The service ID.
          readOnly: true
        name:
          type: string
          description: >
            The machine name of the Service that uniquely identifies it within
            the catalog.
          minLength: 1
          maxLength: 120
          pattern: ^[0-9a-z.-]+$
          example: user-svc
        display_name:
          type: string
          description: The display name of the Service.
          minLength: 1
          maxLength: 120
          example: User Service
        description:
          type: string
          description: Optionally provide a description of the Service.
          nullable: true
          maxLength: 2048
        custom_fields:
          $ref: "#/components/schemas/CustomFields"
        labels:
          $ref: "#/components/schemas/Labels"
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        updated_at:
          $ref: "#/components/schemas/UpdatedAt"
    CatalogServiceVulnerabilityAttributes:
      title: CatalogServiceVulnerabilityAttributes
      description: Service-specific attributes describing cross-vulnerability context.
      additionalProperties: false
      properties:
        most_recent_vulnerability_opened_at:
          type: string
          format: date-time
          readOnly: true
          example: 2025-01-02T20:41:45.068Z
        instance_count:
          type: number
          readOnly: true
          example: 1
        vulnerability_count:
          type: number
          readOnly: true
          example: 1
      required:
        - most_recent_vulnerability_opened_at
        - instance_count
        - vulnerability_count
    BaseError:
      type: object
      title: Error
      description: standard error
      required:
        - status
        - title
        - instance
        - detail
      properties:
        status:
          type: integer
          description: >
            The HTTP status code of the error. Useful when passing the response

            body to child properties in a frontend UI. Must be returned as an
            integer.
          readOnly: true
        title:
          type: string
          description: |
            A short, human-readable summary of the problem. It should not
            change between occurences of a problem, except for localization.
            Should be provided as "Sentence case" for direct use in the UI.
          readOnly: true
        type:
          type: string
          description: The error type.
          readOnly: true
        instance:
          type: string
          description: |
            Used to return the correlation ID back to the user, in the format
            kong:trace:<correlation_id>. This helps us find the relevant logs
            when a customer reports an issue.
          readOnly: true
        detail:
          type: string
          description: >
            A human readable explanation specific to this occurence of the
            problem.

            This field may contain request/entity data to help the user
            understand

            what went wrong. Enclose variable values in square brackets. Should
            be

            provided as "Sentence case" for direct use in the UI.
          readOnly: true
    InvalidParameters:
      type: array
      nullable: false
      uniqueItems: true
      minItems: 1
      description: invalid parameters
      items:
        oneOf:
          - $ref: "#/components/schemas/InvalidParameterStandard"
          - $ref: "#/components/schemas/InvalidParameterMinimumLength"
          - $ref: "#/components/schemas/InvalidParameterMaximumLength"
          - $ref: "#/components/schemas/InvalidParameterChoiceItem"
          - $ref: "#/components/schemas/InvalidParameterDependentItem"
    CustomFields:
      type: object
      x-speakeasy-type-override: any
      description: >
        Map of customizable, catalog-defined fields providing information about
        a service.
      additionalProperties:
        x-convert-oneOf: true
        anyOf:
          - $ref: "#/components/schemas/TextCustomField"
          - $ref: "#/components/schemas/NumericCustomField"
          - $ref: "#/components/schemas/BooleanCustomField"
          - $ref: "#/components/schemas/UrlCustomField"
      example:
        owner: John Appleseed
        dashboard:
          name: On-Call Dashboard
          link: https://my-dashboard-svc.io/dashboards/1
    Labels:
      title: Labels
      type: object
      example:
        env: test
      maxProperties: 50
      description: >
        Labels store metadata of an entity that can be used for filtering an
        entity list or for searching across entity types. 


        Keys must be of length 1-63 characters, and cannot start with "kong",
        "konnect", "mesh", "kic", or "_".
      additionalProperties:
        type: string
        pattern: ^[a-z0-9A-Z]{1}([a-z0-9A-Z-._]*[a-z0-9A-Z]+)?$
        minLength: 1
        maxLength: 63
    CreatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity creation date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    UpdatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity update date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    InvalidParameterStandard:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          $ref: "#/components/schemas/InvalidRules"
        source:
          type: string
          example: body
        reason:
          type: string
          example: is a required field
          readOnly: true
      required:
        - field
        - reason
    InvalidParameterMinimumLength:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - min_length
            - min_digits
            - min_lowercase
            - min_uppercase
            - min_symbols
            - min_items
            - min
        minimum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must have at least 8 characters
          readOnly: true
      required:
        - field
        - reason
        - rule
        - minimum
    InvalidParameterMaximumLength:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - max_length
            - max_items
            - max
        maximum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must not have more than 8 characters
          readOnly: true
      required:
        - field
        - reason
        - rule
        - maximum
    InvalidParameterChoiceItem:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - enum
        reason:
          type: string
          example: is a required field
          readOnly: true
        choices:
          type: array
          uniqueItems: true
          readOnly: true
          nullable: false
          minItems: 1
          items: {}
        source:
          type: string
          example: body
      required:
        - field
        - reason
        - rule
        - choices
    InvalidParameterDependentItem:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: true
          enum:
            - dependent_fields
        reason:
          type: string
          example: is a required field
          readOnly: true
        dependents:
          type: array
          uniqueItems: true
          nullable: true
          items: {}
          readOnly: true
        source:
          type: string
          example: body
      required:
        - field
        - rule
        - reason
        - dependents
    TextCustomField:
      type: string
      nullable: true
    NumericCustomField:
      type: number
      nullable: true
    BooleanCustomField:
      type: boolean
      nullable: true
    UrlCustomField:
      type: object
      nullable: true
      required:
        - name
        - link
      properties:
        name:
          description: The human-readable name of the URL link.
          type: string
          example: On-Call Dashboard
        link:
          description: The href value of the URL link.
          type: string
          format: uri-reference
          example: https://my-dashboard-svc.io/dashboards/1
    InvalidRules:
      description: invalid parameters rules
      type: string
      readOnly: true
      nullable: true
      enum:
        - required
        - is_array
        - is_base64
        - is_boolean
        - is_date_time
        - is_integer
        - is_null
        - is_number
        - is_object
        - is_string
        - is_uuid
        - is_fqdn
        - is_arn
        - unknown_property
        - missing_reference
        - is_label
        - matches_regex
        - invalid
        - is_supported_network_availability_zone_list
        - is_supported_network_cidr_block
        - is_supported_provider_region
        - type
  examples:
    UnauthorizedExample:
      value:
        status: 401
        title: Unauthorized
        instance: kong:trace:8347343766220159418
        detail: Unauthorized
    ForbiddenExample:
      value:
        status: 403
        title: Forbidden
        instance: kong:trace:2723154947768991354
        detail: You do not have permission to perform this action
  securitySchemes:
    konnectAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        The Konnect access token is meant to be used by the Konnect dashboard
        and the decK CLI authenticate with.
    personalAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The personal access token is meant to be used as an alternative to
        basic-auth when accessing Konnect via APIs.

        You can generate a Personal Access Token (PAT) from the [personal access
        token page](https://cloud.konghq.com/global/account/tokens/) in the
        Konnect dashboard.

        The PAT token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer kpat_xgfT...'`
    systemAccountAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The system account access token is meant for automations and
        integrations that are not directly associated with a human identity.

        You can generate a system account Access Token by creating a system
        account and then obtaining a system account access token for that
        account.

        The access token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer spat_i2Ej...'`
```
