List customers with per-instance CVE exposure.

Return a paginated, customer-centric view of CVE exposure. Customers are
first selected when an instance's latest reported downstream release has
a matching release-image CVE posture. All instances for selected customers
are then returned with per-instance CVE counts sourced from SDK-reported
running images or uploaded support bundles. Each customer's top-level CVE
counts come from its selected worst instance (null when no instance has
data), preserving a real instance's posture instead of synthesizing counts
across mixed releases. Reporting instances also include the resolved and
introduced CVE counts for upgrading supported Helm and Embedded Cluster
instances to the latest release currently available on their reported
channel when both releases have complete scan data. Each customer includes
the recommendation with the highest-severity reduction. Airgap instances
without SDK reporting are returned only when another instance selects their
customer; they carry the license channel's latest-release CVE posture as
context.
The severity filter accepts a set (repeatable and/or comma-separated) and
keeps customers whose selected worst instance has at least one CVE in any
selected severity; customers without CVE data are excluded while a severity
filter is active. Counts
in the response always cover all four severities. With
includeSnapshot=true, both the customer page and an unfiltered snapshot are
derived from the authorized fleet's hydrated runtime rows. The snapshot
reports the total authorized app-customer population, the number impacted
by critical or high CVEs, and active instances with critical CVEs by
reported channel release without a second customer-impact request. Requires
the Security Center team feature; teams without it receive 403.

Required RBAC Policy: kots/app/[:appid]/license/[:licenseid]/read

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required

App identifier

Query Params
int64
Defaults to 20

Page size

int64

Current page

Customer search term, resolved through the same OpenSearch-backed engine
as POST /customers/search and supporting its exact query syntax: a bare
term is a fuzzy/prefix name match; name:, type:, channels.name:,
customId:, email:, and airgap: prefixes target specific fields.

severity
array of strings

One or more severities (critical, high, medium, low) to filter customers
by; repeatable and/or comma-separated. A customer is included when its
selected worst instance has at least one finding in any selected severity.
Empty means no filtering.

severity
boolean

Include unfixable CVEs in counts (default false)

boolean

Include the unfiltered fleet-wide customer-impact snapshot and derive the
returned customer page from that same authorized population. Snapshot
requests cannot be combined with search or severity filters.

string

Sort order: customerName, criticalCVEs, totalCVEs, or instanceCount
(default criticalCVEs)

Responses

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json