Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gsonCVE-2023-2976 guava: insecure temporary directory creationCVE-2021-22569 protobuf-java: potential DoS in the parsing procedure for binary dataCVE-2022-3509 protobuf-java: Textformat parsing issue leads to DoSCVE-2022-3510 protobuf-java: Message-Type Extensions parsing issue leads to DoSCVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol BuffersCVE-2022-3171 protobuf-java: timeout in parser leads to DoSCVE-2025-55163 netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS VulnerabilityCVE-2025-55163 netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS VulnerabilityCVE-2026-33871 netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame floodCVE-2026-42587 netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompressionCVE-2026-56819 io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leakGHSA-xpw8-rcwv-8f8p io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset AttackCVE-2021-21295 netty: possible request smuggling in HTTP/2 due missing validationCVE-2021-21409 netty: Request smuggling via content-length headerCVE-2026-47244 netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streamsCVE-2026-48043 netty-codec-http2: netty-codec-http2: Denial of Service due to resource leakCVE-2026-50560 netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handlingCVE-2026-59900 io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2CVE-2023-26464 log4j1-socketappender: DoS via hashmap loggingCVE-2026-2332 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsingCVE-2023-40167 jetty: Improper validation of HTTP/1 content-lengthCVE-2024-6763 org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authorityCVE-2026-10050 In Eclipse Jetty, the Digest authentication server-side component uses ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-cqqj-4p63-rrmm HTTP Request Smuggling in NettyGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-4gq5-ch57-c2mg Arbitrary Code Execution in jackson-databindGHSA-4w82-r329-3q67 Deserialization of Untrusted Data in jackson-databindGHSA-5p34-5m6p-p58g jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-645p-88qh-w398 Arbitrary Code Execution in jackson-databindGHSA-6fpp-rgj9-8rwc Deserialization of untrusted data in FasterXML jackson-databindGHSA-85cw-hj65-qqv9 Polymorphic Typing issue in FasterXML jackson-databindGHSA-9mxf-g3x6-wv74 Server-Side Request Forgery (SSRF) in jackson-databindGHSA-c8hm-7hpq-7jhg com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted DataGHSA-f3j5-rmmp-3fc5 Improper Input Validation in jackson-databindGHSA-f9hv-mg5h-xcw9 Deserialization of Untrusted Data in jackson-databind due to polymorphic deserializationGHSA-fmmc-742q-jg75 jackson-databind polymorphic typing issueGHSA-gjmw-vf9h-g25v jackson-databind polymorphic typing issueGHSA-gww7-p5w4-wrfv Deserialization of Untrusted Data in jackson-databindGHSA-h822-r4r5-v8jg Polymorphic Typing issue in FasterXML jackson-databindGHSA-mx7p-6679-8g3q Polymorphic Typing in FasterXML jackson-databindGHSA-mx9v-gmh4-mgqw Deserialization of Untrusted Data in jackson-databindGHSA-p43x-xfjf-5jhr jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-q93h-jc49-78gg jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-x2w5-5m2g-7h5m XML External Entity Reference (XXE) in jackson-databindGHSA-5j33-cvvr-w245 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.