# Preflight CVE Validator

> Preflight CVE Validator is a paid API for AI agents from preflight402.com, paid per call via x402, $0.05/call, status unknown (last checked 2026-10-02).

Checks whether CVE identifiers are real, published, or rejected — catching hallucinated vulnerability references before an agent acts on them.

## Facts

- Endpoint: POST https://preflight402.com/v1/cve/check?utm_source=zero.xyz
- Price: $0.05/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/preflight-cve-validator-6503adae
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_0mxEEFA7G-dSCdIlCYohf

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability preflight-cve-validator-6503adae -d '<json body>'
```

Example prompt: Before we do anything with these CVEs — CVE-2024-12345, CVE-2023-99999, and CVE-2021-44228 — can you verify they're all real and not hallucinated, and tell me whether each one is published or rejected along with its severity?

## When to prefer this

Use this endpoint when an AI model or agent has produced CVE identifiers and you need to confirm they are real before taking action — filing tickets, alerting teams, or scheduling patches. Prefer this over general web search when you need a structured, machine-readable existence and status check with severity and an authoritative record link, especially for detecting hallucinated advisory references in LLM outputs.

## Known failure modes

- CVE ID format does not match pattern (^CVE-\d{4}-\d{4,}$) — request rejected with validation error
- Batch exceeds 20 IDs — request rejected
- CVE ID is syntactically valid but not yet in the database — returned as non-existent
- Payment failure via x402 protocol — call not processed
- Network timeout or service unavailability

## How this service works

Call before acting on CVE identifiers produced by a model. Returns whether each CVE record exists and its state (published or rejected), with severity and the official CVE record link. Catches fabricated advisory references. Does not tell you whether to patch.

## Output

For each submitted CVE ID, the endpoint returns whether the record exists in the official CVE database, its current state (published or rejected), its severity rating, and a direct link to the official CVE record. Does not provide patch recommendations.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "ids": {
   "type": "array",
   "items": {
    "type": "string",
    "pattern": "^CVE-\\d{4}-\\d{4,}$"
   },
   "maxItems": 20,
   "minItems": 1
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/preflight-cve-validator-6503adae/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from preflight402.com](https://www.zero.xyz/host/preflight402.com/llms.txt)
