This scanner fails randomly (almost weekly) with very little idea as to why. Re-running sometimes works and sometimes fails repeatedly. It is very brittle.
For example, from a log file just now:
WARN - Unable to update 1 or more Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities.
2025-08-28 10:44:23,210 org.owasp.dependencycheck.Engine:713
DEBUG - Update Error
org.owasp.dependencycheck.data.update.exception.UpdateException: Error updating the NVD Data
at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi(NvdApiDataSource.java:399)
at org.owasp.dependencycheck.data.update.NvdApiDataSource.update(NvdApiDataSource.java:117)
at org.owasp.dependencycheck.Engine.doUpdates(Engine.java:903)
at org.owasp.dependencycheck.Engine.initializeAndUpdateDatabase(Engine.java:708)
at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:634)
at org.owasp.dependencycheck.App.runScan(App.java:269)
at org.owasp.dependencycheck.App.run(App.java:201)
at org.owasp.dependencycheck.App.main(App.java:93)
Caused by: java.lang.NullPointerException: Cannot read the array length because "bytes" is null
at java.base/java.lang.String.<init>(String.java:1425)
at io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient._next(NvdCveClient.java:418)
at io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient.next(NvdCveClient.java:357)
at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi(NvdApiDataSource.java:355)
... 7 common frames omitted
2025-08-28 10:44:23,210 org.owasp.dependencycheck.Engine:1175
ERROR - Unable to continue dependency-check analysis.
2025-08-28 10:44:23,210 org.owasp.dependencycheck.Engine:1176
DEBUG -
org.owasp.dependencycheck.exception.NoDataException: No documents exist
at org.owasp.dependencycheck.Engine.ensureDataExists(Engine.java:1160)
at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:638)
at org.owasp.dependencycheck.App.runScan(App.java:269)
at org.owasp.dependencycheck.App.run(App.java:201)
at org.owasp.dependencycheck.App.main(App.java:93)
2025-08-28 10:44:23,219 org.owasp.dependencycheck.App:217
ERROR - One or more fatal errors occurred
Any idea what is going on?