Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Bitbucket Dependency Scanner 0.8.0 - Error updating the NVD Data

Paul S
Contributor
August 28, 2025

This scanner fails randomly (almost weekly) with very little idea as to why. Re-running sometimes works and sometimes fails repeatedly. It is very brittle.

For example, from a log file just now:

WARN  - Unable to update 1 or more Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities.

2025-08-28 10:44:23,210 org.owasp.dependencycheck.Engine:713

DEBUG - Update Error

org.owasp.dependencycheck.data.update.exception.UpdateException: Error updating the NVD Data

at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi(NvdApiDataSource.java:399)

at org.owasp.dependencycheck.data.update.NvdApiDataSource.update(NvdApiDataSource.java:117)

at org.owasp.dependencycheck.Engine.doUpdates(Engine.java:903)

at org.owasp.dependencycheck.Engine.initializeAndUpdateDatabase(Engine.java:708)

at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:634)

at org.owasp.dependencycheck.App.runScan(App.java:269)

at org.owasp.dependencycheck.App.run(App.java:201)

at org.owasp.dependencycheck.App.main(App.java:93)

Caused by: java.lang.NullPointerException: Cannot read the array length because "bytes" is null

at java.base/java.lang.String.<init>(String.java:1425)

at io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient._next(NvdCveClient.java:418)

at io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient.next(NvdCveClient.java:357)

at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi(NvdApiDataSource.java:355)

... 7 common frames omitted

2025-08-28 10:44:23,210 org.owasp.dependencycheck.Engine:1175

ERROR - Unable to continue dependency-check analysis.

2025-08-28 10:44:23,210 org.owasp.dependencycheck.Engine:1176

DEBUG - 

org.owasp.dependencycheck.exception.NoDataException: No documents exist

at org.owasp.dependencycheck.Engine.ensureDataExists(Engine.java:1160)

at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:638)

at org.owasp.dependencycheck.App.runScan(App.java:269)

at org.owasp.dependencycheck.App.run(App.java:201)

at org.owasp.dependencycheck.App.main(App.java:93)

2025-08-28 10:44:23,219 org.owasp.dependencycheck.App:217

ERROR - One or more fatal errors occurred

 
Any idea what is going on?

0 answers

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events