Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2016-1000031 FileUpload: DiskFileItem file manipulationCVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserializationCVE-2016-1000031 FileUpload: DiskFileItem file manipulationCVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserializationCVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of serviceCVE-2023-24998 FileUpload: FileUpload DoS with excessive partsCVE-2025-48976 apache-commons-fileupload: Apache Commons FileUpload DoS via part headersCVE-2024-22243 springframework: URL Parsing with Host ValidationCVE-2024-22259 springframework: URL Parsing with Host ValidationCVE-2024-22262 springframework: URL Parsing with Host ValidationCVE-2013-6429 Framework: XML External Entity (XXE) injection flawCVE-2013-6430 Framework: org.spring.web.util.JavaScriptUtils.javaScriptEscape insufficient escaping of charactersCVE-2015-3192 Framework: denial-of-service attack with XML inputCVE-2024-38809 org.springframework:spring-web: Spring Framework DoS via conditional HTTP requestCVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of serviceCVE-2023-24998 FileUpload: FileUpload DoS with excessive partsCVE-2025-48976 apache-commons-fileupload: Apache Commons FileUpload DoS via part headersCVE-2024-22243 springframework: URL Parsing with Host ValidationCVE-2024-22259 springframework: URL Parsing with Host ValidationCVE-2024-22262 springframework: URL Parsing with Host ValidationCVE-2013-6429 Framework: XML External Entity (XXE) injection flawCVE-2013-6430 Framework: org.spring.web.util.JavaScriptUtils.javaScriptEscape insufficient escaping of charactersCVE-2015-3192 Framework: denial-of-service attack with XML inputCVE-2024-38809 org.springframework:spring-web: Spring Framework DoS via conditional HTTP requestYour dependencies cross-checked against the OSV vulnerability database.
GHSA-c4q5-6c82-3qpw Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux ApplicationsGHSA-hh32-7344-cg2f Authorization bypass in Spring SecurityGHSA-mf92-479x-3373 Spring Security HTTP Headers Are not Written Under Some ConditionsGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-7x9j-7223-rg5m Improper Access Control in commons-fileuploadGHSA-hh32-7344-cg2f Authorization bypass in Spring SecurityGHSA-wmv4-5w76-vp9g Authorization Bypass in Spring SecurityGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methodsGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-7v6m-28jr-rg84 Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression LanguageGHSA-rmrm-75hp-phr2 Improper Input Validation in Hibernate ValidatorGHSA-x83m-pf6f-pf9g hibernate-validator Cross-site Scripting vulnerabilityGHSA-293q-567p-wmwq Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client CertificatesGHSA-gq28-h5vg-8prx Privilege escalation in spring securityGHSA-3chg-m5w7-qfv5 Spring Framework Cross-site Scripting via JavaScriptUtilsGHSA-6p4f-wcwh-5vvm Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resourcesGHSA-72pg-x5f8-j25j Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFluxGHSA-957g-f97v-vppc Spring Framework Cross-site Scripting via JSP Form TagsGHSA-cjpg-rgq5-fr37 Spring Framework Multipart Request Smuggling in Spring MVC and WebFluxGHSA-f93f-g33r-8pcp Improper Restriction of XML External Entity Reference in Spring FrameworkGHSA-g5vr-rgqm-vf78 Spring Framework Path Traversal vulnerabilityGHSA-h3qp-gqrc-q736 Spring Framework Open Redirect in Spring MVC and WebFluxCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.