Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2019-20444 netty: HTTP request smugglingCVE-2019-20444 netty: HTTP request smugglingCVE-2019-20444 netty: HTTP request smugglingCVE-2019-20444 netty: HTTP request smugglingCVE-2019-20444 netty: HTTP request smugglingCVE-2019-20444 netty: HTTP request smugglingCVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2025-49128 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocationCVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2021-37136 netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed dataCVE-2021-37137 netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary wayCVE-2019-20445 netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length headerCVE-2021-21290 netty: Information disclosure via the local system temporary directoryCVE-2021-21295 netty: possible request smuggling in HTTP/2 due missing validationCVE-2021-21409 netty: Request smuggling via content-length headerCVE-2021-43797 netty: control chars in header names may lead to HTTP request smugglingCVE-2024-47535 netty: Denial of Service attack on windows app using NettyCVE-2025-25193 netty: Denial of Service attack on windows app using NettyCVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)Your dependencies cross-checked against the OSV vulnerability database.
GHSA-4gq5-ch57-c2mg Arbitrary Code Execution in jackson-databindGHSA-4w82-r329-3q67 Deserialization of Untrusted Data in jackson-databindGHSA-645p-88qh-w398 Arbitrary Code Execution in jackson-databindGHSA-6fpp-rgj9-8rwc Deserialization of untrusted data in FasterXML jackson-databindGHSA-85cw-hj65-qqv9 Polymorphic Typing issue in FasterXML jackson-databindGHSA-9mxf-g3x6-wv74 Server-Side Request Forgery (SSRF) in jackson-databindGHSA-c8hm-7hpq-7jhg com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted DataGHSA-cggj-fvv3-cqwv FasterXML jackson-databind allows unauthenticated remote code execution GHSA-f3j5-rmmp-3fc5 Improper Input Validation in jackson-databindGHSA-f9hv-mg5h-xcw9 Deserialization of Untrusted Data in jackson-databind due to polymorphic deserializationGHSA-fmmc-742q-jg75 jackson-databind polymorphic typing issueGHSA-gjmw-vf9h-g25v jackson-databind polymorphic typing issueGHSA-gww7-p5w4-wrfv Deserialization of Untrusted Data in jackson-databindGHSA-h592-38cm-4ggp jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code executionGHSA-h822-r4r5-v8jg Polymorphic Typing issue in FasterXML jackson-databindGHSA-mx7p-6679-8g3q Polymorphic Typing in FasterXML jackson-databindGHSA-mx9v-gmh4-mgqw Deserialization of Untrusted Data in jackson-databindGHSA-p43x-xfjf-5jhr jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-q93h-jc49-78gg jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-qr7j-h6gg-jmgc Deserialization of Untrusted Data in jackson-databindGHSA-qxxx-2pp7-5hmx jackson-databind is vulnerable to a deserialization flawGHSA-rfx6-vp9g-rh7v jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypassGHSA-x2w5-5m2g-7h5m XML External Entity Reference (XXE) in jackson-databindGHSA-288c-cq4h-88gq XML External Entity (XXE) Injection in Jackson DatabindGHSA-57j2-w4cx-62h2 Deeply nested json in jackson-databindCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.