Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserializationCVE-2026-40984 micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requestsCVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2025-22235 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposedCVE-2026-40973 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directoryCVE-2026-22733 Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpointsCVE-2024-22243 springframework: URL Parsing with Host ValidationCVE-2024-22259 springframework: URL Parsing with Host ValidationCVE-2024-22262 springframework: URL Parsing with Host ValidationCVE-2024-38809 org.springframework:spring-web: Spring Framework DoS via conditional HTTP requestCVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...CVE-2024-38816 spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResourceCVE-2024-38819 org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworksCVE-2026-41842 spring-framework: Spring Framework: Denial of Service when resolving static resourcesCVE-2026-41845 org.springframework: Spring Framework: Cross-site scripting (XSS) via incorrect JavaScript escapingCVE-2024-38828 org.springframework:spring-webmvc: DoS via Spring MVC controller method with byte[] parameterCVE-2025-41242 org.springframework/spring-webmvc: Spring Framework MVC path traversal vulnerabilityCVE-2026-22737 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template viewsCVE-2026-22745 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on WindowsCVE-2026-41841 Spring MVC and WebFlux applications are vulnerable to Information Disc ...CVE-2026-41843 spring-webflux: spring-webmvc: Spring Framework: Information Disclosure via Path TraversalCVE-2026-41844 Spring Framework: Spring Framework: Open Redirect via crafted linkCVE-2026-41846 Spring Framework: Spring Framework: Cross-site scripting (XSS) via user-supplied values in JSP form tagsCVE-2026-41853 Spring Framework: Spring Framework: Request smuggling vulnerability in Spring MVC and WebFluxCVE-2026-22735 org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent EventsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-5j33-cvvr-w245 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityGHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly appliedGHSA-83qj-6fr2-vhqg Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTGHSA-fpj8-gq4v-p354 Apache Tomcat - Client certificate verification bypassGHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown userGHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validatedGHSA-vfww-5hm6-hx2j Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control SequencesGHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methodsGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-mgvc-8q2h-5pgc Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpointsGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-gm62-rw4g-vrc4 Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned dataGHSA-pr98-23f8-jwxv QOS.CH logback-core Expression Language Injection vulnerabilityGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-h46c-h94j-95f3 jackson-core can throw a StackoverflowError when processing deeply nested dataGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-3wrr-7qpf-2prh jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()GHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesGHSA-hgj6-7826-r7m5 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)GHSA-j3rv-43j4-c7qm jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiationGHSA-rmj7-2vxq-3g9f jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)GHSA-pfh2-hfmq-phg5 json-path Out-of-bounds Write vulnerabilityGHSA-g3pr-3p32-fp23 Micrometer HTTP server instrumentations DoSGHSA-23hv-mwm6-g8jf Apache Tomcat Session Fixation vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.