Dev.to Security 🔐 Cybersecurity 👁 0 📖 3 min read

17,884 Artifactory Matches and 400 Title Matches: Why Query Choice Changes the Answer

17,884 Artifactory Matches and 400 Title Matches: Why Query Choice Changes the Answer Two queries for the same product, run at the same time, returned numbers that differ by a factor of roughly 45. Neither is wrong. Un

17,884 Artifactory Matches and 400 Title Matches: Why Query Choice Changes the Answer

Two queries for the same product, run at the same time, returned numbers that differ by a factor of roughly 45. Neither is wrong. Understanding why they differ is the difference between using an exposure tool and being misled by one.

The context

JFrog Artifactory is a software supply chain chokepoint. It holds the packages, container images and dependencies that build pipelines resolve. Three vulnerabilities were chained in observed attacks during August and September 2026: CVE-2026-82329 (improper authentication, CVSS 9.8), CVE-2026-42018 (anonymous token exposure, CVSS 7.5) and CVE-2026-42016 (incorrect authorization, CVSS 8.1). CISA added JFrog entries to KEV on 12 September 2026.

The queries and their results

Query Matches
app="JFrog Artifactory" 17,884
title="Artifactory" 400

The difference is large enough to be confusing, so it is worth explaining what each query actually measures.

The app query relies on ZoomEye's product fingerprinting, which identifies software through a combination of response characteristics rather than a single visible string. Artifactory exposes distinctive API endpoints, response headers and error formats, so a fingerprint can match even when the page title does not contain the product name.

The title query matches only pages whose HTML title contains the literal string. Many Artifactory deployments sit behind custom reverse proxies, use a branded login page, or return a title that names the organisation rather than the product. Those instances are invisible to the title query and visible to the fingerprint.

Which number to use

For exposure assessment, the fingerprint query is the more useful starting point, because it is designed to identify the software rather than a string. But the 17,884 figure carries its own caveats:

  • Fingerprint matching has false positives. A reverse proxy or a documentation mirror may present characteristics that resemble the product.
  • Version is not part of the query. The fixed version for the CVE-2026-82329 branch is 7.161.20; the broader fixed release is 7.133.11. Matched instances may be patched.
  • Reachability is not exploitability. Artifactory instances are frequently placed behind authentication gateways or restricted to internal networks, even when a service is detected.
  • Repository deployments are often internal. The public count is a lower bound on total deployment, not an upper bound on risk.

Why this matters for supply chain risk

The distinguishing feature of an artifact repository is its position downstream of nothing and upstream of everything. An attacker who controls it can replace cached packages and abuse publishing credentials, which means the affected systems include every build that pulls from it.

That makes the exposure question different from a typical web application. For most software, the question is whether an instance is reachable. For a repository, the question is also whether the artifacts it serves can be trusted, which is a question no external scan can answer.

A practical method

  1. Use the fingerprint query as the discovery baseline. app="JFrog Artifactory" is the more complete signal.
  2. Do not treat the title count as a contradiction. It measures a narrower thing.
  3. Verify version against 7.133.11 and 7.161.20 on instances you own.
  4. Check for the artifacts of the observed attack. Malicious plugins, unfamiliar administrator accounts and SSH keys attached to accounts that should not have them.
  5. Verify artifact integrity independently. Compare hashes and signatures on production images and build outputs. This is the control that addresses the supply chain consequence rather than the exposure.

The general lesson

Different queries answer different questions. A fingerprint query asks "is this software here." A title query asks "does this page say this word." When the two disagree by a large margin, the disagreement is information: it tells you that the product is frequently deployed in ways that hide its identity, which is itself a relevant fact about how it is operated.

References

  • ZoomEye search results for app="JFrog Artifactory" (17,884) and title="Artifactory" (400), collected 23 September 2026
  • JFrog security advisories for CVE-2026-82329, CVE-2026-42016 and CVE-2026-42018
  • NVD entries for the three CVEs
  • CISA Known Exploited Vulnerabilities Catalog, JFrog entries added 12 September 2026
📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.