Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-8466 Allocation of Resources Without Limits or Throttling vulnerability in ...CVE-2026-43966 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Reque ...CVE-2026-43970 Improper Handling of Highly Compressed Data (Data Amplification) vulne ...CVE-2026-7790 Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ...CVE-2026-43968 CVE-2026-43968 affecting package rabbitmq-server for versions less than 3.13.7-5CVE-2026-47071 Hackney: `ssl:connect/2` post-handshake upgrade has no timeoutCVE-2026-47075 Hackney has CR/LF injection in query parameterCVE-2026-47076 Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded hostCVE-2022-42975 Phoenix before 1.6.14 mishandles check_origin wildcardingCVE-2021-46871 phoenix_html allows Cross-site Scripting in HEEx class attributesGHSA-j3gg-r6gp-95q2 XSS in HEEx class attributesCVE-2026-8468 Plug: Unbounded buffer accumulation in multipart header parsing causes denial of serviceCVE-2026-32688 Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustionCVE-2025-1211 Server-side Request Forgery (SSRF) in hackneyCVE-2025-3864 Hackney fails to properly release HTTP connections to the poolCVE-2026-47069 Hackney has CRLF / header injection via unvalidated `domain` and `path` optionsYour dependencies cross-checked against the OSV vulnerability database.
EEF-CVE-2026-65624 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory ExhaustionEEF-CVE-2026-8466 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboyGHSA-w4f7-4cxr-rv3c cowboy and gun affected by an HTTP Request/Response Splitting vulnerabilityEEF-CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2EEF-CVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1EEF-CVE-2026-43970 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY FrameEEF-CVE-2026-59248 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoSEEF-CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoSEEF-CVE-2026-48591 Stored XSS via unescaped HTML attribute values in earmarkEEF-CVE-2026-47071 SOCKS5 TLS upgrade ignores caller timeout in hackneyEEF-CVE-2026-47075 CR/LF injection in query parameter in hackneyEEF-CVE-2026-47076 SSRF allowlist bypass via percent-encoded host in hackneyGHSA-vq52-99r9-h5pw Server-side Request Forgery (SSRF) in hackneyEEF-CVE-2026-56811 Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of serviceEEF-CVE-2026-56812 Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiffGHSA-p8f7-22gq-m7j9 Phoenix before 1.6.14 mishandles check_origin wildcardingGHSA-5g2h-9x5v-5h3x phoenix_html allows Cross-site Scripting in HEEx class attributesEEF-CVE-2026-56814 Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)EEF-CVE-2026-8468 Unbounded buffer accumulation in multipart header parsing causes denial of service in plugEEF-CVE-2026-32688 Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboyEEF-CVE-2026-43969 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1EEF-CVE-2026-47069 CRLF injection in cookie domain/path options in hackneyGHSA-9fm9-hp7p-53mf Hackney fails to properly release HTTP connections to the poolEEF-CVE-2026-56813 Cookie attribute injection in Plug.Conn.Cookies.encode/2GHSA-j3gg-r6gp-95q2 XSS in HEEx class attributesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.