gitsafehub
github.com/apache/guacamole-client ↗

apache/guacamole-client

scanned 2026-08-08 · git 7fcdce8
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies9Known OSS vulnerabilities50Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 9 found · 1 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2026-47065 mina: mina: Arbitrary Code Execution via Deserialization Bypass
    extensions/guacamole-auth-ldap/pom.xml
    A package you depend on has a known security hole (CVE-2026-47065). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function
    guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2026-14257). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-69152 brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays
    guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2026-69152). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...
    guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2026-16221). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-18446 fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority
    guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2026-18446). Fix: Update that package to its patched version.
  • Minor CVE-2026-10532 Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...
    guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-10532). Fix: Update that package to its patched version.
  • Minor CVE-2026-1225 ch.qos.logback/logback-core: Malicious logback.xml configuration file allows instantiation of arbitrary classes
    guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-1225). Fix: Update that package to its patched version.
  • Minor CVE-2026-9828 Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...
    guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-9828). Fix: Update that package to its patched version.
  • Minor CVE-2025-57349 messageformat has a prototype pollution vulnerability
    guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2025-57349). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 50 found · 8 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-3vx3-xf6q-r5xp Exposure of Resource to Wrong Sphere in Apache Tomcat
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2017-5648). Fix: Update that package to its patched version.
  • Serious GHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly applied
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-43515). Fix: Update that package to its patched version.
  • Serious GHSA-cw54-59pw-4g8c Apache Tomcat Improper Access Control vulnerability
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2016-8735). Fix: Update that package to its patched version.
  • Serious GHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown user
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-43512). Fix: Update that package to its patched version.
  • Serious GHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validated
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-41293). Fix: Update that package to its patched version.
  • Serious GHSA-xcpr-7mr4-h4xq Apache Tomcat - Authentication Bypass
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2024-52316). Fix: Update that package to its patched version.
  • Serious GHSA-fpj8-gq4v-p354 Apache Tomcat - Client certificate verification bypass
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2025-66614). Fix: Update that package to its patched version.
  • Serious MAL-2025-21003 Malicious code in fs (npm)
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/extensions/guacamole-auth-radius/pom.xml
    A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole-common-js/package-lock.json
    A package you depend on has a known security hole (CVE-2026-14257). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole-common-js/package-lock.json
    A package you depend on has a known security hole (CVE-2026-69152). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2m8v-j782-fhvr Socket.IO: Zero-attachment Memory Exhaustion
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole-common-js/package-lock.json
    A package you depend on has a known security hole (CVE-2026-69185). Fix: Update that package to its patched version.
  • Worth fixing GHSA-344f-f5vg-2jfj Potential remote code execution in Apache Tomcat
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2020-9484). Fix: Update that package to its patched version.
  • Worth fixing GHSA-5mp6-jrq3-r938 Apache Tomcat: LockOutRealm treats user names as case-sensitive
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-43513). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8qq4-8jvq-mfw4 Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2017-12616). Fix: Update that package to its patched version.
  • Worth fixing GHSA-fv25-8xcx-gqjc Apache Tomcat - WebSocket authentication header exposure
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-42498). Fix: Update that package to its patched version.
  • Worth fixing GHSA-gx5v-xp9w-j4cg Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-41284). Fix: Update that package to its patched version.
  • Worth fixing GHSA-jjpq-gp5q-8q6w Cross-site scripting in Apache Tomcat
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2019-0221). Fix: Update that package to its patched version.
  • Worth fixing GHSA-v646-rx6w-r3qq Improper Access Control in Apache Tomcat
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2016-5388). Fix: Update that package to its patched version.
  • Worth fixing GHSA-xjgh-84hx-56c5 Unrestricted Upload of File with Dangerous Type Apache Tomcat
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2017-12617). Fix: Update that package to its patched version.
  • Worth fixing GHSA-563x-q5rq-57qp Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2026-24880). Fix: Update that package to its patched version.
  • Worth fixing GHSA-jc7p-5r39-9477 Improper Input Validation in Apache Tomcat
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/pom.xml
    A package you depend on has a known security hole (CVE-2016-6816). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2qqx-w9hr-q5gx angular vulnerable to regular expression denial of service via the $resource service
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2023-26117). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2vrf-hf26-jrp5 angular vulnerable to regular expression denial of service via the angular.copy() utility
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2023-26116). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4w4v-5hc9-xrr2 angular vulnerable to super-linear runtime due to backtracking
    /workdirs/scan-58ab8e5b-645b-4796-aed5-457f280755eb/guacamole/src/main/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2024-21490). Fix: Update that package to its patched version.
… 25 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.