gitsafehub
github.com/davisking/dlib ↗

davisking/dlib

scanned 2026-06-30 · git cf82c2c
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependenciesKnown OSS vulnerabilities33Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 30s

Vulnerable dependencies — Trivy none found ✓

Packages you depend on that have known security holes (CVEs).

Nothing found by this check. ✓

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 33 found · 5 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious CVE-2021-20308 Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-20308). Fix: Update that package to its patched version.
  • Serious CVE-2021-23158 A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of se
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-23158). Fix: Update that package to its patched version.
  • Serious CVE-2021-23165 A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-23165). Fix: Update that package to its patched version.
  • Serious CVE-2024-45508 HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2024-45508). Fix: Update that package to its patched version.
  • Serious CVE-2024-46478 HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2024-46478). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-14153 In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libjpeg
    A package you depend on has a known security hole (CVE-2020-14153). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-64505 LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2025-64505). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-64506 LIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or RGB/RGBA images
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2025-64506). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-64720 LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2025-64720). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-65018 LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2025-65018). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-66293 LIBPNG has an out-of-bounds read in png_image_read_composite
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2025-66293). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22695 LIBPNG has a heap buffer over-read in png_image_read_direct_scaled (regression from CVE-2025-65018 fix)
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2026-22695). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22801 LIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2026-22801). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25646 LIBPNG has a heap buffer overflow in png_set_quantize
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2026-25646). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2026-33416). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33636 LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/libpng
    A package you depend on has a known security hole (CVE-2026-33636). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-23180 A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-23180). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-23191 A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-23191). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-23206 A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-23206). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-26252 A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-26252). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-26259 A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-26259). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-26948 Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-26948). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-34119 A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-34119). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-34121 An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulne
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-34121). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-40985 A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.
    /workdirs/scan-a3157f10-db4a-4b1a-9447-7d17775c4b9d/dlib/external/zlib
    A package you depend on has a known security hole (CVE-2021-40985). Fix: Update that package to its patched version.
… 8 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited — injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious — typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project — not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.