Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-30861 flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie headerCVE-2026-34531 Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication fo ...CVE-2019-14322 Pallets Werkzeug vulnerable to Path TraversalCVE-2023-25577 python-werkzeug: high resource usage when parsing multipart form data with many fieldsCVE-2024-34069 python-werkzeug: user may execute code on a developer's machineCVE-2024-49766 werkzeug: python-werkzeug: Werkzeug safe_join not safe on WindowsCVE-2025-66221 Werkzeug: Werkzeug: Denial of service via Windows device names in path segmentsCVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensionsCVE-2026-27199 Werkzeug safe_join() allows Windows special device namesCVE-2023-48052 Missing SSL certificate validation in HTTPie v3.2.2 allows attackers t ...CVE-2022-0430 Exposure of Sensitive Information to an Unauthorized Actor in GitHub r ...CVE-2022-24737 HTTPie is a command-line HTTP client. HTTPie has the practical concept ...CVE-2023-32681 python-requests: Unintended leak of Proxy-Authorization headerCVE-2024-35195 requests: subsequent requests to the same host ignore cert verificationCVE-2024-47081 requests: Requests vulnerable to .netrc credentials leak via malicious URLsCVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creationCVE-2026-27205 flask: Flask: Information disclosure via improper caching of session dataCVE-2023-23934 python-werkzeug: cookie prefixed with = can shadow unprefixed cookieYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2023-62 Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxyPYSEC-2026-2151 Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a UsPYSEC-2026-2152 Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passPYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodPYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2023-221 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are apPYSEC-2023-58 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a smPYSEC-2026-1065 Pallets Werkzeug vulnerable to Path TraversalPYSEC-2026-2043 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainPYSEC-2026-2044 Werkzeug safe_join() allows Windows special device names with compound extensionsPYSEC-2026-2045 Werkzeug safe_join not safe on WindowsPYSEC-2026-2046 Werkzeug safe_join() allows Windows special device namesPYSEC-2026-2320 Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previouPYSEC-2022-167 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.PYSEC-2022-34 HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responsePYSEC-2023-242 Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.PYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rePYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLsPYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=FalsePYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system tePYSEC-2023-57 Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised applicationPYSEC-2022-203 ** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.