# Maze - [[PPC] AI Code Security | Maze Code](https://mazehq.com/ai-code-security) - [[PPC] AI SCA | Maze Code](https://mazehq.com/ai-sca) - [[PPC] AI Vulnerability Management | Platform](https://mazehq.com/ai-vulnerability-management) - [[PPC] Book a Demo | Maze](https://mazehq.com/landing-book-a-demo-maze) - [[PPC] Book a Demo | Therapy](https://mazehq.com/therapy-book-a-demo-maze) - [[PPC] Cloud Vulnerability Management | Maze Cloud](https://mazehq.com/cloud-vulnerability-management) - [12 Vulnerability Prioritization Factors and Why Go Beyond Them](https://mazehq.com/learn/12-vulnerability-prioritization-factors-and-why-go-beyond-them) - [2025: The Year Vulnerabilities Broke Every Record](https://mazehq.com/blog/2025-wrapped-the-year-vulnerabilities-broke-every-record) - [5-Step AI Code Security Workflow and 6 Essential Security Tools](https://mazehq.com/learn/5-step-ai-code-security-workflow-and-6-essential-security-tools) - [7 Stages of Vulnerability Mitigation and Top 7 Mitigation Strategies](https://mazehq.com/learn/7-stages-of-vulnerability-mitigation-and-top-7-mitigation-strategies) - [79 Gadgets Hidden in a Single Deserialization Flaw: CVE-2026-25632](https://mazehq.com/blog/79-gadgets-hidden-in-deserialization-flaw) - [A Fix Without an Owner Is Just a Suggestion](https://mazehq.com/blog/remediation-ownership) - [AI Security: Development vs. Production Risks and How to Mitigate Them](https://mazehq.com/learn/ai-security-development-vs-production-risks-and-how-to-mitigate-them) - [AI Vulnerability Analysis in Action: CVE-2025-27363](https://mazehq.com/blog/ai-vulnerability-analysis-in-action-cve-2025-27363) - [AI Vulnerability Remediation Developers Actually Want to Use](https://mazehq.com/blog/ai-remediation-developers-actually-want-to-use) - [An Analyst’s Take on Maze: AI That Actually Moves the Needle on Vulnerability Management](https://mazehq.com/resource/analysts-take-on-maze) - [Application Security Checklist: 14 Steps Across the SDLC](https://mazehq.com/learn/application-security-checklist-14-steps-across-the-sdlc) - [Application Security: Risks, Strategies, and Modern AppSec Essentials](https://mazehq.com/learn/application-security-risks-strategies-and-modern-appsec-essentials) - [Blog](https://mazehq.com/blog) - [Book a Demo](https://mazehq.com/demo) - [Build your own agent](https://mazehq.com/resource/build-your-own-agent) - [Checkbox Security – Compliance Driven Security is Bound to Fail](https://mazehq.com/blog/checkbox-security-compliance-driven-security-is-bound-to) - [Cloud Application Security: Risks, Technologies, and Best Practices](https://mazehq.com/learn/cloud-application-security) - [Code security isn’t dead](https://mazehq.com/blog/code-security-isnt-dead) - [Common Vulnerabilities and Exposures (CVE): Basics and Best Practices](https://mazehq.com/learn/common-vulnerabilities-and-exposures-cve-basics-and-best-practices) - [Contact us](https://mazehq.com/contact-us) - [Content styleguide](https://mazehq.com/styleguide) - [CVE Remediation in Practice: Process, Examples, and Pro Tips](https://mazehq.com/learn/cve-remediation-in-practice-process-examples-and-pro-tips) - [CVSS Score: Components, Use Cases, and 5 Ways to Go Beyond CVSS](https://mazehq.com/learn/cvss-score-components-use-cases-and-5-ways-to-go-beyond-cvss) - [Cyber Peterborough Presents: A Tech Deep Dive](https://mazehq.com/event/cyber-peterborough-presents-a-tech-deep-div) - [Datasheets](https://mazehq.com/resources/datasheets) - [Dependency Management: How It Works, Tools, Risks, and Best Practices](https://mazehq.com/learn/dependency-management) - [Events](https://mazehq.com/events) - [Exploitability: The Fastest Way to Fewer False Positives](https://mazehq.com/blog/exploitability) - [Ferris Wheel Bar at re:Invent 2026](https://mazehq.com/event/ferris-wheel-bar-at-reinvent-2026) - [Fix-ready Jira tickets, straight from Maze](https://mazehq.com/blog/fix-ready-jira-tickets-straight-from-maze) - [From Rules to Reasoning: The Shift That Made Maze Possible](https://mazehq.com/blog/from-rules-to-reasoning-the-shift-that-made-maze-possible) - [fwd:cloudsec Europe Social](https://mazehq.com/event/fwdcloudsec-europe-social) - [Gartner Vulnerability Management: 7 Key Takeaways](https://mazehq.com/learn/gartner-vulnerability-management-7-key-takeaways) - [Homepage](https://mazehq.com/) - [How AI Changes the Speed of Public Exploits](https://mazehq.com/blog/how-ai-changes-the-speed-of-public-exploits) - [How Static Code Analysis Works, 5 Types of Tools, Pros and Cons](https://mazehq.com/learn/how-static-code-analysis-works-5-types-of-tools-pros-and-cons) - [How will I know my agent works?](https://mazehq.com/resource/how-will-i-know-my-agent-works) - [Introducing Maze Code: Code Security You Can Finally Trust](https://mazehq.com/blog/maze-code) - [KubeCon After Party @ Clark Planetarium](https://mazehq.com/event/kubecon-after-party-clark-planetarium) - [Latio’s 2025 Maze Datasheet](https://mazehq.com/resource/latio-maze-datasheet) - [Launching Maze: AI Agents for Vulnerability Management](https://mazehq.com/blog/launching-maze-ai-agents-for-vulnerability-management) - [Learning Center](https://mazehq.com/learn) - [Managing vulnerabilities requires knowing your business context](https://mazehq.com/blog/managing-vulnerabilities-requires-knowing-your-business-context) - [Manifold & Maze invite: Agentic Workforce Security Dinner](https://mazehq.com/event/manifold-maze-invite-agentic-workforce-security-dinner) - [Matt Johansen’s First Look at Maze](https://mazehq.com/resource/matt-johansens-first-look-at-maze) - [Maze + Wiz](https://mazehq.com/resource/maze-wiz) - [Maze AI-SAST: The AI Security Engineer for Your Code](https://mazehq.com/blog/maze-ai-sast-the-ai-security-engineer-for-your-code) - [Maze Cloud](https://mazehq.com/platform/cloud) - [Maze Code](https://mazehq.com/platform/code) - [Maze Code Datasheet](https://mazehq.com/resource/maze-code-datasheet) - [Maze Code found a Langfuse SSO bug. Are you affected? Find out how to fix it.](https://mazehq.com/blog/maze-code-found-a-langfuse-sso-bug-are-you-affected-find-out-how-to-fix-it) - [Maze Code found an account takeover bug in Saleor](https://mazehq.com/blog/maze-code-found-an-account-takeover-bug-in-saleor) - [Maze Datasheet](https://mazehq.com/resource/maze-datasheet) - [Maze Named a Cloud Security Segment Leader in the 2025 Latio Cloud Security Report](https://mazehq.com/blog/maze-named-a-cloud-security-segment-leader-in-latio-report) - [Maze Padel Social – London](https://mazehq.com/event/maze-padel-social-london) - [Meet Maze: AI Agents That Bring Clarity to Vulnerability Chaos](https://mazehq.com/blog/meet-maze) - [Mile High OWASP September Meetup](https://mazehq.com/event/mile-high-owasp-september-meetup) - [Our Story](https://mazehq.com/our-story) - [OWASP LA October Virtual Meetup](https://mazehq.com/event/owasp-la-september-virtual-meetup) - [Patching: the dirty secrets and how to fix them](https://mazehq.com/blog/patching-the-dirty-secrets-and-how-to-fix-them) - [Platform](https://mazehq.com/platform) - [Privacy Policy](https://mazehq.com/privacy-policy) - [Product Privacy Policy](https://mazehq.com/privacy-policy/product) - [Reachability Analysis: How It Works, Methods, and Best Practices](https://mazehq.com/learn/reachability-analysis-how-it-works-methods-and-best-practices) - [Resources](https://mazehq.com/resources) - [SAST vs SCA: 5 Key Differences and How to Choose](https://mazehq.com/learn/sast-vs-sca-5-key-differences-and-how-to-choose) - [SAST vs. DAST: 6 Key Differences and How to Choose](https://mazehq.com/learn/sast-vs-dast-6-key-differences-and-how-to-choose) - [SAST: Static Application Security Testing Explained](https://mazehq.com/learn/sast-static-application-security-testing-explained) - [SCA Security Explained: Capabilities, Challenges, and Best Practices](https://mazehq.com/learn/sca-security-explained-capabilities-challenges-and-best-practices) - [Should CISOs Build or Buy?](https://mazehq.com/resource/should-cisos-build-or-buy) - [Software Composition Analysis: How It Works + 6 Best Practices](https://mazehq.com/learn/software-composition-analysis-how-it-works-6-best-practices) - [Software Supply Chain Attacks: Types, Examples & 5 Defensive Measures](https://mazehq.com/learn/software-supply-chain-attacks) - [The Cross-Platform False Positive Problem: Why Vulnerability Scanners Flag Windows CVEs on Linux](https://mazehq.com/blog/cross-platform-false-positive-problem) - [The Hidden Problem With CVSS: The Same CVE Gets Different Scores](https://mazehq.com/blog/hidden-problem-with-cvss) - [The Language Barrier: Why Security and Engineering Are Never Aligned](https://mazehq.com/resource/the-language-barrier) - [The Vulnerability Management Problem](https://mazehq.com/blog/the-problem-of-vulnerability-management) - [There’s a ten-year-old key confusion bug in PyJWT, fixed in 2.14.0](https://mazehq.com/blog/theres-a-ten-year-old-key-confusion-bug-in-pyjwt-fixed-in-2-14-0) - [Top 18 Application Security Best Practices for Leading AppSec](https://mazehq.com/learn/top-application-security-best-practices-for-leading-appsec) - [Top 3 Vibe Coding Security Risks and 5 Ways to Prevent Them](https://mazehq.com/learn/top-3-vibe-coding-security-risks-and-5-ways-to-prevent-them) - [Videos](https://mazehq.com/resources/videos) - [Vulnerability Déjà Vu: Why the Same Bug Keeps Coming Back](https://mazehq.com/blog/vulnerability-deja-vu) - [Vulnerability Management Tools: Key Features and 14 Tools to Watch](https://mazehq.com/learn/vulnerability-management-tools-key-features-and-14-tools-to-watch) - [Vulnerability Management: Process, Metrics, and Technologies](https://mazehq.com/learn/vulnerability-management-process-metrics-and-technologies) - [Webinar: The hardest problems we solved building Maze](https://mazehq.com/event/webinar-the-hardest-problems-we-solved-building-maze) - [Why we can’t just auto-fix all our vulnerabilities away, yet](https://mazehq.com/blog/why-we-cant-just-auto-fix-all-our-vulnerabilities-away-yet) - [XZ Utils Backdoor: Impact, Mitigation, and Why Vulnerability Management Must Evolve](https://mazehq.com/learn/xz-utils-backdoor-impact-mitigation-and-why-vulnerability-management-must-evolve) ## API - [OpenAPI description](https://mazehq.com/openapi.json) — public, read-only content endpoints