gitsafehub
github.com/jasonkneen/symphony ↗

jasonkneen/symphony

scanned 2026-08-15 · git 8001b52
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies16Known OSS vulnerabilities27Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 16 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2026-39803 Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked`
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39803). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-39804 bandit: Bandit: Denial of Service due to memory exhaustion via WebSocket permessage-deflate compression
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39804). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-39806 Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39806). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42786 bandit: Bandit: Denial of Service via uncontrolled memory growth in WebSocket connections
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-42786). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-39805 bandit: Bandit: HTTP Request Smuggling via Duplicate Content-Length Headers
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39805). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-39807 Bandit trusts client-supplied URI scheme on plaintext connections
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39807). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42788 bandit: Bandit: Denial of Service via oversized HTTP/2 frames
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-42788). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-32686 Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-32686). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48862 mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-48862). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49754 mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-49754). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49753 mint: Content-Length header accepts non-RFC "+" sign prefix
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-49753). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-32689 Phoenix: Long-poll NDJSON body splitting causes large memory allocation
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-32689). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-8468 Plug: Unbounded buffer accumulation in multipart header parsing causes denial of service
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-8468). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49755 Req vulnerable to unbounded archive/compression extraction triggered by response content-type
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-49755). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49756 Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-49756). Fix: Update that package to its patched version.
  • Minor CVE-2026-48861 mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
    elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-48861). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 27 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing EEF-CVE-2026-39803 HTTP/1 chunked body reader ignores length cap in bandit
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39803). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-39804 WebSocket permessage-deflate inflate has no output-size cap in bandit
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39804). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-39805 CL.CL HTTP request smuggling via duplicate Content-Length in bandit
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39805). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-39806 HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39806). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-39807 Client-supplied URI scheme trusted without transport verification in bandit
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-39807). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-42786 WebSocket fragmented message reassembly unbounded in bandit
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-42786). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-42788 HTTP/2 frame size limit checked after body is buffered in bandit
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-42788). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-32686 Unbounded exponent in decimal enables unauthenticated DoS
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-32686). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-58226 Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-58226). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-48862 Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-48862). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-49753 HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-49753). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-49754 HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-49754). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-56810 mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-56810). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-58229 Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-58229). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-59246 Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-59246). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-59249 Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-59249). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-32689 Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-32689). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-56811 Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-56811). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-56812 Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-56812). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-54892 Plug: quadratic-time decoding of nested query/body parameters enables denial of service
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-54892). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-56814 Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-56814). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-8468 Unbounded buffer accumulation in multipart header parsing causes denial of service in plug
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-8468). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-49755 Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-49755). Fix: Update that package to its patched version.
  • Worth fixing EEF-CVE-2026-49756 Multipart form-data header injection in Req via unescaped name/filename/content_type
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-49756). Fix: Update that package to its patched version.
  • Minor EEF-CVE-2026-48861 CRLF injection in HTTP/1 request line via unvalidated method in Mint
    /workdirs/scan-b9f4d137-f13d-4b56-8ba0-0e6e91be5400/elixir/mix.lock
    A package you depend on has a known security hole (CVE-2026-48861). Fix: Update that package to its patched version.
… 2 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.