Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2017-5929 logback: Serialization vulnerability in SocketServer and ServerSocketReceiverCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2017-5929 logback: Serialization vulnerability in SocketServer and ServerSocketReceiverCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2017-5929 logback: Serialization vulnerability in SocketServer and ServerSocketReceiverCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2020-26945 mybatis: mishandles deserialization of object streams which could result in remote code executionCVE-2022-22970 springframework: DoS via data binding to multipartFile or servlet partCVE-2022-22968 Framework: Data Binding Rules VulnerabilityCVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...CVE-2018-15756 springframework: DoS Attack via Range RequestsCVE-2023-38286 Spring-boot-admin sandbox bypass via crafted HTMLCVE-2023-2976 guava: insecure temporary directory creationCVE-2017-3523 mysql-connector-java: Improper automatic deserialization of binary data (CPU Apr 2017)CVE-2018-3258 mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018)CVE-2017-3586 mysql-connector-java: Connector/J unspecified vulnerability (CPU Apr 2017)CVE-2019-2692 mysql-connector-java: privilege escalation in MySQL connectorCVE-2022-21363 mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL ConnectorsCVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2018-3258 mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018)CVE-2019-2692 mysql-connector-java: privilege escalation in MySQL connectorCVE-2021-2471 mysql-connector-java: unauthorized access to criticalCVE-2022-21363 mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL ConnectorsCVE-2020-26945 mybatis: mishandles deserialization of object streams which could result in remote code executionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-2xxh-f8r3-hvvr Improper Access Control in MySQL Connectors JavaGHSA-4vrv-ch96-6h42 Improper Privilege Management in MySQL Connectors JavaGHSA-g76j-4cxx-23h9 Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors JavaGHSA-jcq3-cprp-m333 Privilege escalation in mysql-connector-javGHSA-m6vm-37g8-gqvh MySQL Connectors takeover vulnerabilityGHSA-pwh7-92h3-mqr6 Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors JavaGHSA-qq48-m4jx-xqh8 "Deserialization errors in MyBatis"GHSA-hh26-6xwr-ggv7 Denial of service in Spring FrameworkGHSA-4gc7-5j7h-4qph Spring Framework DataBinder Case Sensitive Match ExceptionGHSA-g5mm-vmx4-3rg7 Improper handling of case sensitivity in Spring FrameworkGHSA-ffvq-7w96-97p7 Denial of Service in Spring FrameworkGHSA-7gj7-224w-vpr3 Spring-boot-admin sandbox bypass via crafted HTMLGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-2xxh-f8r3-hvvr Improper Access Control in MySQL Connectors JavaGHSA-4vrv-ch96-6h42 Improper Privilege Management in MySQL Connectors JavaGHSA-g76j-4cxx-23h9 Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors JavaGHSA-jcq3-cprp-m333 Privilege escalation in mysql-connector-javGHSA-m6vm-37g8-gqvh MySQL Connectors takeover vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.