Description
Getting vulnerabilities fail with 414 URI Too Long
Environment
- OS: Ubuntu 24.04.4 LTS
- Version: 7.260430.0
Reproducible steps
Steps to create the smallest reproducible scenario:
- add long cpes 50 long cpes to your sbom
- set
VULMATCH_SBOM_ONLY=true in connector config
- run connector
Expected output
Should run without a problem
Actual output
Runs and work fails with 414 URI Too Long
Additional information
running it locally I see
File "/Users/lullah/dev/dogesec/opencti-connectors/external-import/dogesec-vulmatch/src/connector.py", line 303, in <module>
VulmatchConnector().run()
~~~~~~~~~~~~~~~~~~~~~~~^^
File "/Users/lullah/dev/dogesec/opencti-connectors/external-import/dogesec-vulmatch/src/connector.py", line 227, in run
self.get_vulnerabilities(cpes)
~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^
File "/Users/lullah/dev/dogesec/opencti-connectors/external-import/dogesec-vulmatch/src/connector.py", line 120, in get_vulnerabilities
vulnerabilities = self.retrieve(
"v1/cve/objects/",
...<12 lines>...
),
)
File "/Users/lullah/dev/dogesec/opencti-connectors/external-import/dogesec-vulmatch/src/connector.py", line 111, in retrieve
raise VulmatchException(f"Unexpected response for url `{resp.url}`: [{resp.status_code}] {resp.content}")
VulmatchException: Unexpected response for url `https://api.vulmatch.com/v1/cve/objects/?cpes_in_pattern=cpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A-%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A-%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.19426.20044%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.19127.20000%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.19822.20000%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.16130.20156%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.18925.20000%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.16026.20172%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.19328.20000%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.18730.20000%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.19220.20000%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.16827.20138%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A16.0.18827.20000%3A%2A%3A%2A%3A%2A%3A%2A%3Aandroid%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.104.5%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.103.0%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.104.3%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.103.3%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.103.4%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.106.2%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.106.3%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.107.1%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.105.1%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.107%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.104%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.103.1%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.106.1%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.106%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.104.1%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.105%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.103.2%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.104.4%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Aa%3Amicrosoft%3A365_copilot%3A2.104.2%3A%2A%3A%2A%3A%2A%3A%2A%3Aiphone_os%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A-%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A14.0%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A15.0%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A12l%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A12.1%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A6.0.1%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A9.0%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A6.0%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A4.0%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A7.0%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A2.3.3%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A1.0%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A8.0%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A2.3.1%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A2.3.5%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A2.0.1%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A3.2.4%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%2Ccpe%3A2.3%3Ao%3Agoogle%3Aandroid%3A2.2.2%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A&modified_min=2026-03-11T12%3A37%3A30.902507%2B00%3A00&modified_max=2026-06-19T12%3A37%3A30.902555%2B00%3A00&sort=modified_ascending&page=1&page_size=200`: [400] b'<html>\n <head>\n <title>Bad Request</title>\n </head>\n <body>\n <h1><p>Bad Request</p></h1>\n Request Line is too large (4971 > 4094)\n <script defer src="https://static.cloudflareinsights.com/beacon.min.js/v833ccba57c9e4d2798f2e76cebdd09a11778172276447" integrity="sha512-57MDmcccJXYtNnH+ZiBwzC4jb2rvgVCEokYN+L/nLlmO8rfYT/gIpW2A569iJ/3b+0UEasghjuZH/ma3wIs/EQ==" data-cf-beacon=\'{"version":"2024.11.0","token":"1ca092f2e90a49a5bbf0cf7f042555fe","r":1,"server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}\' crossorigin="anonymous"></script>\n</body>\n</html>\n'
Description
Getting vulnerabilities fail with 414 URI Too Long
Environment
Reproducible steps
Steps to create the smallest reproducible scenario:
VULMATCH_SBOM_ONLY=truein connector configExpected output
Should run without a problem
Actual output
Runs and work fails with 414 URI Too Long
Additional information
running it locally I see