Auto Resolve Support by Test Type

Auto Resolve automatically closes vulnerabilities that are no longer detected when re-scanned under the same scan configuration.

Not all test types are eligible for Auto Resolve.

  • Some tests operate at entrypoint level and can be automatically re-validated.
  • Other tests operate at application or host level and require manual review.

Below is the current support matrix.

Auto Resolve Support Matrix

Test TypeAuto Resolve Support
XSS (Reflective)Supported
SQL InjectionSupported
SQL Error MessageSupported
XPath InjectionSupported
NoSQL InjectionSupported
NoSQL Error MessageSupported
Path DisclosureSupported
OS InjectionSupported
Blind Time-based OS InjectionSupported
Remote File Inclusion (RFI)Supported
Local File Inclusion (LFI)Supported
HTML InjectionSupported
CSS InjectionSupported
Iframe InjectionSupported
Insecure Output HandlingSupported
SSRFSupported
Blind SSRFSupported
XXESupported
Server-Side Template Injection (SSTI)Supported
File UploadSupported
High CSRFSupported
Broken JWT AuthenticationSupported
JWT Role BypassSupported
ID EnumerationSupported
Business Constraint BypassSupported
Prototype PollutionSupported
Server-Side JS InjectionSupported
Email Header InjectionSupported
LDAP Error MessageSupported
Session ID in URLSupported
Secret API KeysSupported
Connection StringSupported
Excessive Data ExposureSupported
Prompt InjectionSupported
JavaScript VulnerabilitiesSupported
Insecure CookieSupported
Directory ListingSupported
Brute Force LoginSupported
Open DatabaseSupported
GraphQL IntrospectionSupported
Broken SAMLSupported
Blind Time-based NoSQL InjectionSupported
Date Manipulation (BL_DATES)Supported
Unvalidated RedirectionSupported
Broken Access ControlSupported (requires identical authentication configuration)

Not Supported for Auto Resolve

Test Type
Amazon S3 Takeover
Open Cloud Storage
BOPLA
XSS (Stored)
Version Control System Disclosure
Default Login Location
HTTP Methods (Critical)
Header Security Issues
WordPress Vulnerabilities
Common Files
Insecure TLS Configurations
Insecure Cookie (Weak Session ID)
Misconfigured WebDAV
WebDAV Authentication
LRRL (Rate Limiting)
Nuclei CVE
Improper Assets Management

Notes

  • Auto Resolve works only when the scan configuration remains identical.
  • Application-level and host-level tests are not supported for generic Auto Resolve.
  • Time-based tests may occasionally require manual validation.