View a markdown version of this page

ListImageScanFindings - EC2 Image Builder
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

ListImageScanFindings

Returns a list of image scan findings for your account. Amazon Inspector generates the findings when it scans images that have scanning enabled.

Request Syntax

POST /ListImageScanFindings HTTP/1.1 Content-type: application/json { "filters": [ { "name": "string", "values": [ "string" ] } ], "maxResults": number, "nextToken": "string" }

URI Request Parameters

The request does not use any URI parameters.

Request Body

The request accepts the following data in JSON format.

filters

An array of name value pairs that you can use to filter your results. You can use the following filters to streamline results:

  • imageBuildVersionArn – Filters findings by the image build version that was scanned.

  • imagePipelineArn – Filters findings by the pipeline that created the scanned image.

  • vulnerabilityId – Filters findings by vulnerability ID, for example a CVE ID.

  • severity – Filters findings by severity level.

If you don't request a filter, then all findings in your account are listed.

Type: Array of ImageScanFindingsFilter objects

Array Members: Fixed number of 1 item.

Required: No

maxResults

The maximum number of items to return in a single request.

Type: Integer

Valid Range: Minimum value of 1. Maximum value of 25.

Required: No

nextToken

A token to specify where to start paginating. Use the nextToken value from a previously truncated response.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 65535.

Required: No

Response Syntax

HTTP/1.1 200 Content-type: application/json { "findings": [ { "awsAccountId": "string", "description": "string", "firstObservedAt": number, "fixAvailable": "string", "imageBuildVersionArn": "string", "imagePipelineArn": "string", "inspectorScore": number, "inspectorScoreDetails": { "adjustedCvss": { "adjustments": [ { "metric": "string", "reason": "string" } ], "cvssSource": "string", "score": number, "scoreSource": "string", "scoringVector": "string", "version": "string" } }, "packageVulnerabilityDetails": { "cvss": [ { "baseScore": number, "scoringVector": "string", "source": "string", "version": "string" } ], "referenceUrls": [ "string" ], "relatedVulnerabilities": [ "string" ], "source": "string", "sourceUrl": "string", "vendorCreatedAt": number, "vendorSeverity": "string", "vendorUpdatedAt": number, "vulnerabilityId": "string", "vulnerablePackages": [ { "arch": "string", "epoch": number, "filePath": "string", "fixedInVersion": "string", "name": "string", "packageManager": "string", "release": "string", "remediation": "string", "sourceLayerHash": "string", "version": "string" } ] }, "remediation": { "recommendation": { "text": "string", "url": "string" } }, "severity": "string", "title": "string", "type": "string", "updatedAt": number } ], "nextToken": "string", "requestId": "string" }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

findings

The image scan findings for your account that meet your request filter criteria.

Type: Array of ImageScanFinding objects

Array Members: Maximum number of 25 items.

nextToken

The next token used for paginated responses. When this field isn't empty, there are additional elements that the service hasn't included in this request. Use this token with the next request to retrieve additional objects.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 65535.

requestId

The request ID that uniquely identifies this request.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Errors

For information about the errors that are common to all actions, see Common Error Types.

CallRateLimitExceededException

You have exceeded the permitted request rate for the Amazon EC2 APIs that Image Builder calls on your behalf. Retry with an increasing or variable delay between requests.

HTTP Status Code: 429

ClientException

A generic client error. This error usually indicates that the request failed a validation check, such as when a downstream service rejects a configured value.

HTTP Status Code: 400

ForbiddenException

You are not authorized to perform the requested operation.

HTTP Status Code: 403

InvalidPaginationTokenException

You have provided an invalid pagination token in your request.

HTTP Status Code: 400

InvalidRequestException

The request is malformed or otherwise invalid. Verify the request and try again.

HTTP Status Code: 400

ServiceException

An internal server error occurred while Image Builder processed the request. Retrying the request may succeed.

HTTP Status Code: 500

ServiceUnavailableException

The service is unable to process your request at this time.

HTTP Status Code: 503

Examples

List vulnerability findings for an image build

The following example lists the vulnerability findings that Amazon Inspector detected for the specified image build version.

Sample Request

POST /ListImageScanFindings HTTP/1.1 Content-type: application/json { "filters": [ { "name": "imageBuildVersionArn", "values": [ "arn:aws:imagebuilder:us-west-2:111122223333:image/my-example-recipe/1.0.0/1" ] } ] }

Sample Response

HTTP/1.1 200 Content-type: application/json { "requestId": "233de8e7-3b58-4319-a6af-f6774cf7d371", "findings": [ { "awsAccountId": "111122223333", "imageBuildVersionArn": "arn:aws:imagebuilder:us-west-2:111122223333:image/my-example-recipe/1.0.0/1", "imagePipelineArn": "arn:aws:imagebuilder:us-west-2:111122223333:image-pipeline/my-example-pipeline", "type": "PACKAGE_VULNERABILITY", "description": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: break and reset virtio devices on device_shutdown()", "title": "CVE-2025-38064 - kernel", "remediation": { "recommendation": { "text": "None Provided" } }, "severity": "HIGH", "firstObservedAt": 1767730377.0, "updatedAt": 1767730377.0, "inspectorScore": 7.0, "inspectorScoreDetails": { "adjustedCvss": { "scoreSource": "AMAZON_CVE", "cvssSource": "AMAZON_CVE", "version": "3.1", "score": 7.0, "scoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "adjustments": [] } }, "packageVulnerabilityDetails": { "vulnerabilityId": "CVE-2025-38064", "vulnerablePackages": [ { "name": "kernel", "version": "4.14.355", "epoch": 0, "release": "280.652.amzn2", "arch": "X86_64", "packageManager": "OS", "fixedInVersion": "0:5.15.189-131.202.amzn2", "remediation": "yum update kernel" } ], "source": "AMAZON_CVE", "cvss": [ { "baseScore": 7.0, "scoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1", "source": "AMAZON_CVE" } ], "relatedVulnerabilities": [ "ALAS2-2025-2955", "ALAS2023-2025-1130" ], "sourceUrl": "https://alas.aws.amazon.com/cve/json/v1/CVE-2025-38064.json", "vendorSeverity": "Important", "vendorCreatedAt": 1750204800.0, "vendorUpdatedAt": 1750809600.0, "referenceUrls": [ "https://alas.aws.amazon.com/AL2/ALAS2-2025-2955.html", "https://alas.aws.amazon.com/AL2023/ALAS2023-2025-1130.html" ] }, "fixAvailable": "YES" } ] }

See Also

For more information about using this API in one of the language-specific Amazon SDKs, see the following: