Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-46602 The TIFF decoder does not set a limit on the size of tiles in tiled im ...CVE-2026-33809 golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF fileCVE-2026-33812 golang.org/x/image: golang: golang.org/x/image: Denial of Service due to excessive memory allocation when parsing malicious font filesCVE-2026-33813 golang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsingCVE-2026-46599 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed dataCVE-2026-46601 golang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP imagesCVE-2026-46604 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF imageCVE-2026-25681 golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site ScriptingCVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypassCVE-2026-33814 net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frameCVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processingCVE-2026-46600 golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsingCVE-2025-22870 golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/netCVE-2025-22872 golang.org/x/net/html: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/netCVE-2025-47911 golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/htmlCVE-2025-58190 golang.org/x/net/html: Infinite parsing loop in golang.org/x/netCVE-2026-25680 golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsingCVE-2026-42502 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree renderingCVE-2026-42506 golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsingCVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 inputCVE-2026-42500 Decoding a paletted BMP file with an out-of-range palette index result ...CVE-2026-39824 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windowsYour dependencies cross-checked against the OSV vulnerability database.
GO-2026-4815 OOM from malicious IFD offset in golang.org/x/image/tiffGO-2026-5032 Excessive resource consumption in PackBits decompression in golang.org/x/image/tiffGO-2025-3503 HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/netGO-2025-3595 Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/netGO-2026-5028 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/htmlGO-2026-4961 Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/imageGO-2026-4962 Excessive memory allocation when decoding malicious SFNT in golang.org/x/imageGO-2026-5031 Panic when reading out of bound palette index in golang.org/x/image/bmpGO-2026-5061 Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/imageGO-2026-5062 Lack of limit on tile sizes in x/image/tiff in golang.org/x/imageGO-2026-5066 Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/imageGO-2026-4440 Quadratic parsing complexity in golang.org/x/net/htmlGO-2026-4441 Infinite parsing loop in golang.org/x/netGO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/netGO-2026-5025 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/htmlGO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaGO-2026-5027 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/htmlGO-2026-5029 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/htmlGO-2026-5030 Invoking duplicate attributes can cause XSS in golang.org/x/net/htmlGO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessageGO-2026-5024 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windowsGO-2026-5970 Infinite loop on invalid input in golang.org/x/textGO-2024-2598 Verify panics on certificates with an unknown public key algorithm in crypto/x509GO-2024-2599 Memory exhaustion in multipart form parsing in net/textproto and net/httpGO-2024-2600 Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/httpCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.