Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-46602 The TIFF decoder does not set a limit on the size of tiles in tiled im ...CVE-2026-46604 The TIFF decoder can panic when decoding an invalid image with an out- ...CVE-2023-29407 golang.org/x/image/tiff: excessive CPU consumption in decodingCVE-2023-29408 golang.org/x/image/tiff: TIFF decoder does not place a limit on the size of compressed tile dataCVE-2026-33809 golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF fileCVE-2026-33812 golang.org/x/image: golang: golang.org/x/image: Denial of Service due to excessive memory allocation when parsing malicious font filesCVE-2026-33813 golang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsingCVE-2026-46599 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed dataCVE-2026-46601 golang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP imagesCVE-2026-56852 A norm.Iter can enter an infinite loop when handling input containing ...CVE-2024-24792 Parsing a corrupt or malicious image with invalid color indices can ca ...CVE-2026-42500 Decoding a paletted BMP file with an out-of-range palette index result ...CVE-2026-39824 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windowsYour dependencies cross-checked against the OSV vulnerability database.
GO-2023-1989 Excessive resource consumption in golang.org/x/image/tiffGO-2023-1990 Excessive CPU consumption when decoding 0-height images in golang.org/x/image/tiffGO-2024-2937 Panic when parsing invalid palette-color images in golang.org/x/imageGO-2026-4815 OOM from malicious IFD offset in golang.org/x/image/tiffGO-2026-5032 Excessive resource consumption in PackBits decompression in golang.org/x/image/tiffGO-2026-4961 Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/imageGO-2026-4962 Excessive memory allocation when decoding malicious SFNT in golang.org/x/imageGO-2026-5031 Panic when reading out of bound palette index in golang.org/x/image/bmpGO-2026-5061 Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/imageGO-2026-5062 Lack of limit on tile sizes in x/image/tiff in golang.org/x/imageGO-2026-5066 Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/imageGO-2026-5024 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windowsGO-2026-5970 Infinite loop on invalid input in golang.org/x/textGO-2025-3503 HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/netGO-2025-3563 Request smuggling due to acceptance of invalid chunked data in net/httpGO-2025-3750 Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscallGO-2025-3751 Sensitive headers not cleared on cross-origin redirect in net/httpGO-2025-3849 Incorrect results returned from Rows.Scan in database/sqlGO-2025-3956 Unexpected paths returned from LookPath in os/execGO-2025-4006 Excessive CPU consumption in ParseAddress in net/mailGO-2025-4007 Quadratic complexity when checking name constraints in crypto/x509GO-2025-4008 ALPN negotiation error contains attacker controlled information in crypto/tlsGO-2025-4009 Quadratic complexity when parsing some invalid inputs in encoding/pemGO-2025-4010 Insufficient validation of bracketed IPv6 hostnames in net/urlGO-2025-4011 Parsing DER payload can cause memory exhaustion in encoding/asn1Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.