gitsafehub
github.com/gastaldi/langchain4j ↗

gastaldi/langchain4j

scanned 2026-08-11 · git cbbfb08
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets2Vulnerable dependencies402Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 2 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    docs/docs/integrations/embedding-stores/elasticsearch.md:36
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    document-loaders/langchain4j-document-loader-azure-storage-blob/src/test/java/dev/langchain4j/data/document/loader/azure/storage/blob/LocalAzureBlobStorageDocumentLoaderIT.java:45
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 402 found · 15 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2025-14813). Fix: Update that package to its patched version.
  • Serious CVE-2026-9277 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
    docs/package-lock.json
    A package you depend on has a known security hole (CVE-2026-9277). Fix: Update that package to its patched version.
  • Serious CVE-2026-54466 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...
    docs/package-lock.json
    A package you depend on has a known security hole (CVE-2026-54466). Fix: Update that package to its patched version.
  • Serious CVE-2025-66516 tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
    document-parsers/langchain4j-document-parser-apache-tika/pom.xml
    A package you depend on has a known security hole (CVE-2025-66516). Fix: Update that package to its patched version.
  • Serious CVE-2025-54988 org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
    document-parsers/langchain4j-document-parser-apache-tika/pom.xml
    A package you depend on has a known security hole (CVE-2025-54988). Fix: Update that package to its patched version.
  • Serious CVE-2025-66516 tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
    document-parsers/langchain4j-document-parser-apache-tika/pom.xml
    A package you depend on has a known security hole (CVE-2025-66516). Fix: Update that package to its patched version.
  • Serious CVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
    langchain4j-easy-rag/pom.xml
    A package you depend on has a known security hole (CVE-2025-14813). Fix: Update that package to its patched version.
  • Serious CVE-2025-0851 Deep Java Library path traversal issue
    langchain4j-onnx-scoring/pom.xml
    A package you depend on has a known security hole (CVE-2025-0851). Fix: Update that package to its patched version.
  • Serious CVE-2026-40682 org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
    langchain4j/pom.xml
    A package you depend on has a known security hole (CVE-2026-40682). Fix: Update that package to its patched version.
  • Serious CVE-2026-42027 Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
    langchain4j/pom.xml
    A package you depend on has a known security hole (CVE-2026-42027). Fix: Update that package to its patched version.
  • Serious CVE-2025-0851 Deep Java Library path traversal issue
    pom.xml
    A package you depend on has a known security hole (CVE-2025-0851). Fix: Update that package to its patched version.
  • Serious CVE-2026-40682 org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
    pom.xml
    A package you depend on has a known security hole (CVE-2026-40682). Fix: Update that package to its patched version.
  • Serious CVE-2026-42027 Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
    pom.xml
    A package you depend on has a known security hole (CVE-2026-42027). Fix: Update that package to its patched version.
  • Serious CVE-2025-66516 tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
    pom.xml
    A package you depend on has a known security hole (CVE-2025-66516). Fix: Update that package to its patched version.
  • Serious CVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
    pom.xml
    A package you depend on has a known security hole (CVE-2025-14813). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-8916 org.bouncycastle: BouncyCastle denial of service
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2025-8916). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-5588 bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2026-5588). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-29857 org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2024-29857). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-30171 bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2024-30171). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-30172 org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2024-30172). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34447 org.bouncycastle: Use of Incorrectly-Resolved Name or Reference
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2024-34447). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-8885 bouncycastle: Bouncy Castle denial of service parsing ASN.1 Object Identifiers
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2025-8885). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-0636 bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
    code-execution-engines/langchain4j-code-execution-engine-graalvm-polyglot/pom.xml
    A package you depend on has a known security hole (CVE-2026-0636). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
    code-execution-engines/langchain4j-code-execution-engine-judge0/pom.xml
    A package you depend on has a known security hole (GHSA-r7wm-3cxj-wff9). Fix: Update that package to its patched version.
  • Worth fixing GHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
    code-execution-engines/langchain4j-code-execution-engine-judge0/pom.xml
    A package you depend on has a known security hole (GHSA-72hv-8253-57qq). Fix: Update that package to its patched version.
… 377 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner timed out

Your dependencies cross-checked against the OSV vulnerability database.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OSV-Scanner v1.9.2 · Apache-2.0

error: timeout after 120s

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.