CVE sensor releases
The Common Vulnerabilities and Exposure (CVE) sensor collects vulnerability data from IBM Concert to provide enhanced visibility to your vulnerabilities in Instana.
For more information, see Integrating IBM Concert with Instana.
Release 2.0.14
CVE sensor 2.0.14 is released on 19 December 2025.
Improvements
This release optimizes Concert API polling with enhanced retry logic and validation.
Fixes
This release reactors the CVE sensor to use a single scheduler.
Release 2.0.13
CVE sensor 2.0.13 is released on 4 November 2025.
Fixes
This release fixes the AI data collection feature by disabling the following data collection:
- Detailed attack vector explanations
- Active exploit detection
- Remediation guidance
Release 2.0.12
CVE sensor 2.0.12 is released on 22 October 2025.
Features
This release adds comprehensive vulnerability APIs from Concert to provide the following detailed CVE information:
- Vulnerability descriptions and CVS vector scores
- Detailed attack vector explanations
- Active exploit detection
- Remediation guidance
Improvements
This release provides the following enhancements:
- Implementation of
SelfManagedPeriodicTaskfor periodic task scheduling. - Addition of an explicit HTTP client resource release mechanism to prevent resource leaks.
Release 2.0.9
CVE sensor 2.0.9 is released on 28 July 2025.
Improvements
The CVE sensor's capability method now returns the cve-vulnerability function, which enhances data discovery and insights.
Release 2.0.7
CVE sensor 2.0.7 is released on 21 April 2025.
Improvements
The CVE sensor now supports the float data type for Concert risk score.
Release 2.0.6
CVE sensor 2.0.6 is released on 20 March 2025.
Fix
The CVE sensor now supports handling container image digest for the Instana CVE correlation.
Release 2.0.4
CVE sensor 2.0.4 is released on 25 February 2025.
Improvements
The CVE sensor now supports handling CVE image Uniform Resource Identifier (URI) with custom ports and tags.
Release 2.0.1
CVE sensor 2.0.1 is released on 9 January 2025.
Improvements
The CVE sensor is updated according to the latest changes to the Concert API.
Release 2.0.0
CVE sensor 2.0.0 is released on 9 December 2024.
Improvements
The CVE sensor polls the Concert APIs every 10 minutes to collect vulnerability findings. These vulnerability findings are converted into CVE detections for each container, based on the associated container image.