Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2025-1247 io.quarkus:quarkus-rest: Quarkus REST Endpoint Request Parameter Leakage Due to Shared InstanceCVE-2025-66560 io.quarkus/quarkus-rest: Quarkus REST Worker Thread Exhaustion VulnerabilityCVE-2025-49574 io.quarkus/quarkus-vertx: Quarkus potential data leakCVE-2026-39852 io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requestsCVE-2026-50559 io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded charactersCVE-2025-11965 io.vertx/vertx-core: Eclipse Vert.x Access Control FlawCVE-2025-4949 org.eclipse.jgit: XXE vulnerability in Eclipse JGitCVE-2025-11966 io.vertx/vertx-web: Eclipse Vert.x cross site scriptingYour dependencies cross-checked against the OSV vulnerability database.
GHSA-5rfx-cp42-p624 Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to writeGHSA-phg3-gv66-q38x Quarkus REST Endpoint Request Parameter Leakage Due to Shared InstanceGHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS ConditionGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-3p8m-j85q-pgmj Netty's decoders vulnerable to DoS via zip bomb style attackGHSA-558v-64gr-wgg4 Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread HangGHSA-mj4r-2hfc-f8p6 Netty Lz4FrameDecoder is vulnerable to resource exhaustion GHSA-cm33-6792-r9fm Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)GHSA-mfg7-5gfp-c4w3 Netty: Memory Leak in DNS Record Decoder via Malformed Domain NamesGHSA-cc37-9q2j-3hfv Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV lengthGHSA-h2qv-fj59-j46j Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory ExhaustionGHSA-q6cq-mhr2-jmr5 Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory ExhaustionGHSA-wh89-7897-x99h Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX AddressGHSA-38f8-5428-x5cv Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-EncodingGHSA-4mp9-239f-g9hg Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validationGHSA-57rv-r2g8-2cj3 Netty has HttpClientCodec response desynchronizationGHSA-6cqp-g7gg-8hr5 Netty: Security Control Bypass via CORS Short-Circuit FailureGHSA-6jqx-86gh-f27w Netty SPDY SETTINGS frame count materializes unbounded settings mapGHSA-84h7-rjj3-6jx4 Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoderGHSA-f6hv-jmp6-3vwv Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoSGHSA-gcjf-9mgh-3p7g Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoderGHSA-hvcg-qmg6-jm4c Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permittedGHSA-jppx-w49h-x2qq Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory ExhaustionGHSA-m4cv-j2px-7723 Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsingGHSA-mvh2-crg5-v77c Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.