gitsafehub
github.com/eziosudo/java-sdk ↗

eziosudo/java-sdk

scanned 2026-08-13 · git af65356
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies106Known OSS vulnerabilities2Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 106 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2026-35568 Java-SDK has a DNS Rebinding Vulnerability
    mcp-core/pom.xml
    A package you depend on has a known security hole (CVE-2026-35568). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34237 MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
    mcp-core/pom.xml
    A package you depend on has a known security hole (CVE-2026-34237). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
    mcp-json-jackson2/pom.xml
    A package you depend on has a known security hole (GHSA-r7wm-3cxj-wff9). Fix: Update that package to its patched version.
  • Worth fixing GHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
    mcp-json-jackson2/pom.xml
    A package you depend on has a known security hole (GHSA-72hv-8253-57qq). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
    mcp-json-jackson2/pom.xml
    A package you depend on has a known security hole (CVE-2026-54512). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
    mcp-json-jackson2/pom.xml
    A package you depend on has a known security hole (CVE-2026-54513). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
    mcp-json-jackson2/pom.xml
    A package you depend on has a known security hole (CVE-2026-54514). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
    mcp-json-jackson2/pom.xml
    A package you depend on has a known security hole (CVE-2026-54515). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59888 com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
    mcp-json-jackson2/pom.xml
    A package you depend on has a known security hole (CVE-2026-59888). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-41249 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2025-41249). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-41234 springframework: Reflected download attack in Spring Framework with non-ASCII headers
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2025-41234). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41854 spring-framework: Spring Framework: Server-Side Request Forgery via incorrect host parsing
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-41854). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41842 spring-framework: Spring Framework: Denial of Service when resolving static resources
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-41842). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22737 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-22737). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22740 spring-webflux: Spring WebFlux: Denial of Service via temporary file accumulation
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-22740). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22745 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-22745). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41839 spring-framework: Spring Framework: Privilege escalation via session ID exchange in WebFlux applications
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-41839). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41840 Spring WebFlux applications are vulnerable to Denial of Service (DoS) ...
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-41840). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41841 Spring MVC and WebFlux applications are vulnerable to Information Disc ...
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-41841). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41843 spring-webflux: spring-webmvc: Spring Framework: Information Disclosure via Path Traversal
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-41843). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41844 Spring Framework: Spring Framework: Open Redirect via crafted link
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-41844). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41853 Spring Framework: Spring Framework: Request smuggling vulnerability in Spring MVC and WebFlux
    mcp-spring/mcp-spring-webflux/pom.xml
    A package you depend on has a known security hole (CVE-2026-41853). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-41249 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
    mcp-spring/mcp-spring-webmvc/pom.xml
    A package you depend on has a known security hole (CVE-2025-41249). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41850 spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions
    mcp-spring/mcp-spring-webmvc/pom.xml
    A package you depend on has a known security hole (CVE-2026-41850). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41851 Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation
    mcp-spring/mcp-spring-webmvc/pom.xml
    A package you depend on has a known security hole (CVE-2026-41851). Fix: Update that package to its patched version.
… 81 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 2 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing GHSA-8jxr-pr72-r468 Java-SDK has a DNS Rebinding Vulnerability
    /workdirs/scan-3d87e69a-e997-468b-be06-33c8b8d84125/mcp/pom.xml
    A package you depend on has a known security hole (CVE-2026-35568). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hv2w-8mjj-jw22 MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
    /workdirs/scan-3d87e69a-e997-468b-be06-33c8b8d84125/mcp/pom.xml
    A package you depend on has a known security hole (CVE-2026-34237). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.