Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserializationCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2019-10219 hibernate-validator: safeHTML validator allows XSSCVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messagesCVE-2023-1932 hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSSCVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language InjectionCVE-2022-27772 Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-bootCVE-2025-22235 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposedCVE-2026-40973 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directoryCVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS VulnerabilityCVE-2024-22243 springframework: URL Parsing with Host ValidationCVE-2024-22259 springframework: URL Parsing with Host ValidationCVE-2024-22262 springframework: URL Parsing with Host ValidationCVE-2024-38809 org.springframework:spring-web: Spring Framework DoS via conditional HTTP requestCVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...CVE-2020-5398 springframework: RFD attack via Content-Disposition Header sourced from request input by Spring MVC or Spring WebFlux ApplicationCVE-2024-38819 org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworksCVE-2026-41842 spring-framework: Spring Framework: Denial of Service when resolving static resourcesCVE-2026-41845 org.springframework: Spring Framework: Cross-site scripting (XSS) via incorrect JavaScript escapingCVE-2026-22745 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on WindowsCVE-2026-41841 Spring MVC and WebFlux applications are vulnerable to Information Disc ...CVE-2026-41843 spring-webflux: spring-webmvc: Spring Framework: Information Disclosure via Path TraversalCVE-2026-41844 Spring Framework: Spring Framework: Open Redirect via crafted linkCVE-2026-41846 Spring Framework: Spring Framework: Cross-site scripting (XSS) via user-supplied values in JSP form tagsYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.