ListImageScanFindings
Returns a list of image scan findings for your account. Amazon Inspector generates the findings when it scans images that have scanning enabled.
Request Syntax
POST /ListImageScanFindings HTTP/1.1
Content-type: application/json
{
"filters": [
{
"name": "string",
"values": [ "string" ]
}
],
"maxResults": number,
"nextToken": "string"
}
URI Request Parameters
The request does not use any URI parameters.
Request Body
The request accepts the following data in JSON format.
- filters
-
An array of name value pairs that you can use to filter your results. You can use the following filters to streamline results:
-
imageBuildVersionArn– Filters findings by the image build version that was scanned. -
imagePipelineArn– Filters findings by the pipeline that created the scanned image. -
vulnerabilityId– Filters findings by vulnerability ID, for example a CVE ID. -
severity– Filters findings by severity level.
If you don't request a filter, then all findings in your account are listed.
Type: Array of ImageScanFindingsFilter objects
Array Members: Fixed number of 1 item.
Required: No
-
- maxResults
-
The maximum number of items to return in a single request.
Type: Integer
Valid Range: Minimum value of 1. Maximum value of 25.
Required: No
- nextToken
-
A token to specify where to start paginating. Use the
nextTokenvalue from a previously truncated response.Type: String
Length Constraints: Minimum length of 1. Maximum length of 65535.
Required: No
Response Syntax
HTTP/1.1 200
Content-type: application/json
{
"findings": [
{
"awsAccountId": "string",
"description": "string",
"firstObservedAt": number,
"fixAvailable": "string",
"imageBuildVersionArn": "string",
"imagePipelineArn": "string",
"inspectorScore": number,
"inspectorScoreDetails": {
"adjustedCvss": {
"adjustments": [
{
"metric": "string",
"reason": "string"
}
],
"cvssSource": "string",
"score": number,
"scoreSource": "string",
"scoringVector": "string",
"version": "string"
}
},
"packageVulnerabilityDetails": {
"cvss": [
{
"baseScore": number,
"scoringVector": "string",
"source": "string",
"version": "string"
}
],
"referenceUrls": [ "string" ],
"relatedVulnerabilities": [ "string" ],
"source": "string",
"sourceUrl": "string",
"vendorCreatedAt": number,
"vendorSeverity": "string",
"vendorUpdatedAt": number,
"vulnerabilityId": "string",
"vulnerablePackages": [
{
"arch": "string",
"epoch": number,
"filePath": "string",
"fixedInVersion": "string",
"name": "string",
"packageManager": "string",
"release": "string",
"remediation": "string",
"sourceLayerHash": "string",
"version": "string"
}
]
},
"remediation": {
"recommendation": {
"text": "string",
"url": "string"
}
},
"severity": "string",
"title": "string",
"type": "string",
"updatedAt": number
}
],
"nextToken": "string",
"requestId": "string"
}
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
- findings
-
The image scan findings for your account that meet your request filter criteria.
Type: Array of ImageScanFinding objects
Array Members: Maximum number of 25 items.
- nextToken
-
The next token used for paginated responses. When this field isn't empty, there are additional elements that the service hasn't included in this request. Use this token with the next request to retrieve additional objects.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 65535.
- requestId
-
The request ID that uniquely identifies this request.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 1024.
Errors
For information about the errors that are common to all actions, see Common Error Types.
- CallRateLimitExceededException
-
You have exceeded the permitted request rate for the Amazon EC2 APIs that Image Builder calls on your behalf. Retry with an increasing or variable delay between requests.
HTTP Status Code: 429
- ClientException
-
A generic client error. This error usually indicates that the request failed a validation check, such as when a downstream service rejects a configured value.
HTTP Status Code: 400
- ForbiddenException
-
You are not authorized to perform the requested operation.
HTTP Status Code: 403
- InvalidPaginationTokenException
-
You have provided an invalid pagination token in your request.
HTTP Status Code: 400
- InvalidRequestException
-
The request is malformed or otherwise invalid. Verify the request and try again.
HTTP Status Code: 400
- ServiceException
-
An internal server error occurred while Image Builder processed the request. Retrying the request may succeed.
HTTP Status Code: 500
- ServiceUnavailableException
-
The service is unable to process your request at this time.
HTTP Status Code: 503
Examples
List vulnerability findings for an image build
The following example lists the vulnerability findings that Amazon Inspector detected for the specified image build version.
Sample Request
POST /ListImageScanFindings HTTP/1.1
Content-type: application/json
{
"filters": [
{
"name": "imageBuildVersionArn",
"values": [
"arn:aws:imagebuilder:us-west-2:111122223333:image/my-example-recipe/1.0.0/1"
]
}
]
}
Sample Response
HTTP/1.1 200
Content-type: application/json
{
"requestId": "233de8e7-3b58-4319-a6af-f6774cf7d371",
"findings": [
{
"awsAccountId": "111122223333",
"imageBuildVersionArn": "arn:aws:imagebuilder:us-west-2:111122223333:image/my-example-recipe/1.0.0/1",
"imagePipelineArn": "arn:aws:imagebuilder:us-west-2:111122223333:image-pipeline/my-example-pipeline",
"type": "PACKAGE_VULNERABILITY",
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: break and reset virtio devices on device_shutdown()",
"title": "CVE-2025-38064 - kernel",
"remediation": {
"recommendation": {
"text": "None Provided"
}
},
"severity": "HIGH",
"firstObservedAt": 1767730377.0,
"updatedAt": 1767730377.0,
"inspectorScore": 7.0,
"inspectorScoreDetails": {
"adjustedCvss": {
"scoreSource": "AMAZON_CVE",
"cvssSource": "AMAZON_CVE",
"version": "3.1",
"score": 7.0,
"scoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"adjustments": []
}
},
"packageVulnerabilityDetails": {
"vulnerabilityId": "CVE-2025-38064",
"vulnerablePackages": [
{
"name": "kernel",
"version": "4.14.355",
"epoch": 0,
"release": "280.652.amzn2",
"arch": "X86_64",
"packageManager": "OS",
"fixedInVersion": "0:5.15.189-131.202.amzn2",
"remediation": "yum update kernel"
}
],
"source": "AMAZON_CVE",
"cvss": [
{
"baseScore": 7.0,
"scoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1",
"source": "AMAZON_CVE"
}
],
"relatedVulnerabilities": [
"ALAS2-2025-2955",
"ALAS2023-2025-1130"
],
"sourceUrl": "https://alas.aws.amazon.com/cve/json/v1/CVE-2025-38064.json",
"vendorSeverity": "Important",
"vendorCreatedAt": 1750204800.0,
"vendorUpdatedAt": 1750809600.0,
"referenceUrls": [
"https://alas.aws.amazon.com/AL2/ALAS2-2025-2955.html",
"https://alas.aws.amazon.com/AL2023/ALAS2023-2025-1130.html"
]
},
"fixAvailable": "YES"
}
]
}
See Also
For more information about using this API in one of the language-specific Amazon SDKs, see the following: