Current Behavior
Aliases in create requests are ignored. the alias shows up in the response but is ignored in gui/db.
Request :
{
"vulnId": "INT-111-111",
"source": "INTERNAL",
"title": "test",
"severity": "MEDIUM",
"cvssV2Vector": null,
"cvssV3Vector": null,
"owaspRRVector": null,
"cwes": [],
"affectedComponents": [],
"aliases" : [{
"cveId": " CVE-2026-21304"
}]
}
Response:
{
"vulnId": "INT-111-111",
"source": "INTERNAL",
"title": "test",
"cwes": [],
"severity": "MEDIUM",
"components": [],
"serviceComponents": [],
"uuid": "911a662d-5271-4fbf-b585-c5889aa44cd5",
"aliases": [
{
"cveId": "CVE-2026-21304"
}
],
"affectedProjectCount": 0,
"affectedActiveProjectCount": 0,
"affectedInactiveProjectCount": 0,
"affectedComponents": []
}
In update requests the aliases are just ignored
request:
{
"uuid": "911a662d-5271-4fbf-b585-c5889aa44cd5",
"vulnId": "INT-111-111",
"source": "INTERNAL",
"title": "tests",
"severity": "MEDIUM",
"cvssV2Vector": null,
"cvssV3Vector": null,
"owaspRRVector": null,
"cwes": [],
"affectedComponents": [],
"aliases" : [{
"cveId": " CVE-2026-21304"
}]
}
Response:
{
"vulnId": "INT-111-111",
"source": "INTERNAL",
"title": "tests",
"cwes": [],
"severity": "MEDIUM",
"components": [],
"uuid": "911a662d-5271-4fbf-b585-c5889aa44cd5",
"aliases": [],
"affectedProjectCount": 0,
"affectedActiveProjectCount": 0,
"affectedInactiveProjectCount": 0
}
Proposed Behavior
Add support for aliases for internal vulnerabilities.
Checklist
Current Behavior
Aliases in create requests are ignored. the alias shows up in the response but is ignored in gui/db.
Request :
{ "vulnId": "INT-111-111", "source": "INTERNAL", "title": "test", "severity": "MEDIUM", "cvssV2Vector": null, "cvssV3Vector": null, "owaspRRVector": null, "cwes": [], "affectedComponents": [], "aliases" : [{ "cveId": " CVE-2026-21304" }] }Response:
{ "vulnId": "INT-111-111", "source": "INTERNAL", "title": "test", "cwes": [], "severity": "MEDIUM", "components": [], "serviceComponents": [], "uuid": "911a662d-5271-4fbf-b585-c5889aa44cd5", "aliases": [ { "cveId": "CVE-2026-21304" } ], "affectedProjectCount": 0, "affectedActiveProjectCount": 0, "affectedInactiveProjectCount": 0, "affectedComponents": [] }In update requests the aliases are just ignored
request:
{ "uuid": "911a662d-5271-4fbf-b585-c5889aa44cd5", "vulnId": "INT-111-111", "source": "INTERNAL", "title": "tests", "severity": "MEDIUM", "cvssV2Vector": null, "cvssV3Vector": null, "owaspRRVector": null, "cwes": [], "affectedComponents": [], "aliases" : [{ "cveId": " CVE-2026-21304" }] }Response:
{ "vulnId": "INT-111-111", "source": "INTERNAL", "title": "tests", "cwes": [], "severity": "MEDIUM", "components": [], "uuid": "911a662d-5271-4fbf-b585-c5889aa44cd5", "aliases": [], "affectedProjectCount": 0, "affectedActiveProjectCount": 0, "affectedInactiveProjectCount": 0 }Proposed Behavior
Add support for aliases for internal vulnerabilities.
Checklist