Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-35568 Java-SDK has a DNS Rebinding VulnerabilityCVE-2026-34237 MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)GHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS ConditionCVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypassCVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code executionCVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS ResolutionCVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modifiedCVE-2026-59888 com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java RecordsCVE-2025-41249 org.springframework/spring-core: Spring Framework Annotation Detection VulnerabilityCVE-2025-41234 springframework: Reflected download attack in Spring Framework with non-ASCII headersCVE-2026-41854 spring-framework: Spring Framework: Server-Side Request Forgery via incorrect host parsingCVE-2026-41842 spring-framework: Spring Framework: Denial of Service when resolving static resourcesCVE-2026-22737 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template viewsCVE-2026-22740 spring-webflux: Spring WebFlux: Denial of Service via temporary file accumulationCVE-2026-22745 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on WindowsCVE-2026-41839 spring-framework: Spring Framework: Privilege escalation via session ID exchange in WebFlux applicationsCVE-2026-41840 Spring WebFlux applications are vulnerable to Denial of Service (DoS) ...CVE-2026-41841 Spring MVC and WebFlux applications are vulnerable to Information Disc ...CVE-2026-41843 spring-webflux: spring-webmvc: Spring Framework: Information Disclosure via Path TraversalCVE-2026-41844 Spring Framework: Spring Framework: Open Redirect via crafted linkCVE-2026-41853 Spring Framework: Spring Framework: Request smuggling vulnerability in Spring MVC and WebFluxCVE-2025-41249 org.springframework/spring-core: Spring Framework Annotation Detection VulnerabilityCVE-2026-41850 spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressionsCVE-2026-41851 Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluationYour dependencies cross-checked against the OSV vulnerability database.
GHSA-8jxr-pr72-r468 Java-SDK has a DNS Rebinding VulnerabilityGHSA-hv2w-8mjj-jw22 MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.