products

Supported Products

Attestd currently covers 39 software products. Coverage is intentionally narrow: each product in the set has acceptable sentinel rates in NVD (where evaluated), well-maintained CPE records, and enough historical CVE data to produce reliable synthesis output.

Pass the exact slug shown below as the product parameter. Product names are normalized to lowercase with spaces replaced by underscores, so Apache Log4j and log4j resolve to the same record.

Databases
Apache Cassandracassandra

Distributed wide-column store from the ASF. CVE history includes serious issues in optional features (e.g. UDF execution). Keyword uses the full phrase "Apache Cassandra" to limit noise.

High-throughput writes, time series at scale, multi-region clusters

Apache CouchDBcouchdb

Document database with replication. Includes critical historical RCEs (e.g. CVE-2022-24706, KEV). Tracked as apache:couchdb.

Offline-first apps, sync-heavy workloads

Apache Derbyapache_derby

Apache's embedded Java relational database (JDBC). NVD tracks it as apache:derby with a modest but usable CVE history for server-side SQL and network exposure scenarios.

Embedded databases, Java tooling, test fixtures

Couchbase Servercouchbase

Distributed document database with search and analytics. Tracked as couchbase:couchbase_server in NVD with substantive CVE ranges.

Mobile sync backends, session stores, personalization

Elasticsearchelasticsearch

Elastic's search and analytics engine. Standard semver in NVD under elastic:elasticsearch.

Search, log aggregation, observability stacks

MariaDBmariadb

Community fork of MySQL. Single NVD namespace mariadb:mariadb with strong CVE coverage and semver-style versions.

MySQL-compatible deployments, managed databases

Microsoft SQL Servermssql

Enterprise RDBMS from Microsoft. NVD commonly uses dotted build numbers (e.g. 15.0.x) rather than marketing years.

Enterprise apps, .NET stacks, Azure SQL siblings

MongoDBmongodb

Document-oriented database. MongoDB is a CNA; NVD entries often include explicit CPE ranges.

Application data, analytics, AI/ML pipelines

MySQLmysql

Oracle's open-source RDBMS. NVD merges pre- and post-acquisition vendor namespaces (mysql:mysql and oracle:mysql) for complete historical coverage.

LAMP/LEMP stacks, SaaS backends, managed MySQL

Oracle Databaseoracle_db

Oracle's flagship RDBMS. NVD uses numeric release trains (e.g. 19.x, 21.x), not marketing labels like 19c.

ERP, finance, large packaged applications

PostgreSQLpostgresql

The PostgreSQL open-source relational database. Coverage includes server-side vulnerabilities and privilege bypass issues in the query engine.

Application databases, analytics workloads

Redisredis

In-memory data structure store. CVE records are merged across two NVD vendor namespaces reflecting the 2021 vendor name change from redislabs to redis.

Caching layers, session stores, message queues

SQLitesqlite

Embedded SQL engine. CVE history is thinner than client-server databases but includes real memory-safety issues; tracked as sqlite:sqlite.

Mobile apps, browsers, embedded devices, desktop software

Web servers & proxies
Apache HTTP Serverapache_httpd

The Apache HTTP Server Project's web server, tracked as apache:http_server in NVD. Coverage includes module-specific vulnerabilities such as mod_proxy and mod_cgi.

Web servers, shared hosting infrastructure

Caddycaddy

Go-based HTTP server with automatic HTTPS. Tracked as caddyserver:caddy in NVD. Newer project; added after passing eligibility checks.

Developer environments, reverse proxies, AI deployment endpoints

HAProxyhaproxy

High-availability load balancer and TCP/HTTP proxy. HAProxy is its own CNA and self-publishes CVEs, producing high-quality NVD records. CVE history concentrates in HTTP header parsing and request smuggling.

Load balancers, API gateways, high-availability frontends

NGINXnginx

HTTP server and reverse proxy. CVE coverage spans pre- and post-F5 acquisition records, merged across two NVD vendor namespaces.

Web servers, load balancers, API gateways

Squidsquid

Caching proxy for HTTP, HTTPS, and FTP. Tracked as squid-cache:squid in NVD with an extensive CVE history in HTTP request parsing and authentication handling.

Forward proxies, content caching, network security layers

Traefiktraefik

Cloud-native reverse proxy and ingress controller for Kubernetes and container environments. Tracked as traefik:traefik in NVD.

Kubernetes ingress, microservice routing, AI model serving endpoints

Varnish Cachevarnish

HTTP accelerator for content-heavy dynamic websites. NVD uses two CPE namespaces (varnish-cache:varnish and varnish_cache_project:varnish_cache); both are queried and merged.

CDN edge caching, high-traffic web frontends

Messaging & streaming
Containers & orchestration
Infrastructure & runtimes

Supply chain monitoring: In addition to these 39 CVE-covered infrastructure products, Attestd monitors 50 PyPI packages for malicious publishes, security yanks, and OSV advisories. See the full list and details.

eligibility criteria

How products are selected

Not every software product produces reliable output from a CPE-based synthesis pipeline. A product must meet all three criteria before it is added:

01

Sentinel rate below 50%

A sentinel range is an NVD record that names a product as affected but omits version data. High sentinel rates mean the pipeline cannot determine which versions are affected, producing unreliable results. Products with ecosystem-level CVE noise (CMSes, plugin platforms) typically fail this criterion.

02

At least 10 CVEs with valid version ranges

Products with fewer than 10 usable records produce output that may reflect NVD coverage gaps rather than actual security posture. Thin datasets do not provide enough signal for accurate risk classification.

03

Complete CPE namespace coverage

When a vendor is acquired or renames itself, NVD may maintain two separate CPE namespaces for the same product. Both must be queried and merged to avoid silently missing historical CVEs. nginx, log4j, Redis, and MySQL each required this treatment.

coverage requests

Request a product

Coverage expands based on demand. Email support@attestd.io with the product name and your use case. Products with structural NVD data quality problems (high sentinel rates, inconsistent CPE namespaces) cannot be added until those issues are resolved upstream.