Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URLCVE-2019-5477 A command injection vulnerability in Nokogiri v1.10.3 and earlier allo ...GHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsCVE-2018-14404 libxml2: NULL pointer dereference in xmlXPathCompOpEval() function in xpath.cCVE-2018-25032 zlib: A flaw found in zlib when compressing (not decompressing) certain inputsCVE-2019-13118 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid characterCVE-2019-18197 libxslt: use after free in xsltCopyText in transform.c could lead to information disclosureCVE-2019-5815 chromium-browser: Heap buffer overflow in BlinkCVE-2020-7595 libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situationsCVE-2021-30560 Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 a ...CVE-2021-3517 libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.cCVE-2021-3518 libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.cCVE-2021-41098 rubygem-nokogiri: XEE on JRubyCVE-2022-24836 nokogiri: ReDoS in HTML encoding detectionCVE-2022-24839 nokogiri: Uncontrolled Resource Consumption in org.cyberneko.html (nokogiri fork)CVE-2022-29181 rubygem-nokogiri: Improper Handling of Unexpected Data Type in NokogiriGHSA-7rrm-v45f-jp64 Update packaged dependency libxml2 from 2.9.10 to 2.9.12GHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-cgx6-hpwq-fhv5 Integer Overflow or Wraparound in libxml2 affects NokogiriGHSA-fq42-c5rg-92c2 Vulnerable dependencies in NokogiriGHSA-gx8x-g87m-h5q6 Denial of Service (DoS) in Nokogiri on JRubyGHSA-mrxw-mxhj-p664 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEsGHSA-v6gp-9mmm-c6p5 Out-of-bounds Write in zlib affects NokogiriCVE-2019-13117 libxslt: an xsl number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbersCVE-2021-3537 libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery modeYour dependencies cross-checked against the OSV vulnerability database.
GHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsGHSA-cr5j-953j-xw5p Nokogiri Command Injection VulnerabilityGHSA-qxcg-xjjg-66mj Nokogiri vulnerable to libxslt protection mechanism bypassGHSA-242x-7cm6-4w8j Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerabilityGHSA-286v-pcf5-25rc Nokogiri Implements libxml2 version vulnerable to null pointer dereferencingGHSA-2rr5-8q37-2w7h Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRubyGHSA-4hm9-844j-jmxp Uninitialized read in Nokogiri gemGHSA-59gp-qqm7-cw4j Nokogiri has vulnerable dependencies on libxml2 and libxsltGHSA-5prr-v3j2-97mh Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-6qvp-r6r3-9p7h Nokogiri NULL Pointer DereferenceGHSA-7553-jr98-vx47 libxml as used in Nokogiri has an infinite loop in a certain end-of-file situationGHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-cf46-6xxh-pc75 libxslt Type Confusion vulnerability that affects NokogiriGHSA-cgx6-hpwq-fhv5 Integer Overflow or Wraparound in libxml2 affects NokogiriGHSA-crjr-9rc5-ghw8 Nokogiri Inefficient Regular Expression ComplexityGHSA-fq42-c5rg-92c2 Vulnerable dependencies in NokogiriGHSA-gx8x-g87m-h5q6 Denial of Service (DoS) in Nokogiri on JRubyGHSA-jc36-42cf-vqwj Nokogiri affected by zlib's Out-of-bounds Write vulnerabilityGHSA-jw9f-hh49-cvp9 Nokogiri contains libxml Out-of-bounds Write vulnerabilityGHSA-mrxw-mxhj-p664 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEsGHSA-v2fc-qm4h-8hqv Nokogiri XSLT transform has a memory leakGHSA-v4f8-2847-rwm7 Nokogiri Implements libxml2 version vulnerable to use-after-freeGHSA-v6gp-9mmm-c6p5 Out-of-bounds Write in zlib affects NokogiriGHSA-vmfx-gcfq-wvm2 Nokogiri implementation of libxslt vulnerable to heap corruptionGHSA-vr8q-g5c7-m54m Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.