gitsafehub
github.com/jdubois/spring-boot-cosmos-db ↗

jdubois/spring-boot-cosmos-db

scanned 2026-08-13 · git 26d2cdd
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies36Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 36 found · 3 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+
    pom.xml
    A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
  • Serious CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
    pom.xml
    A package you depend on has a known security hole (CVE-2016-1000027). Fix: Update that package to its patched version.
  • Serious CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+
    pom.xml
    A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-10219 hibernate-validator: safeHTML validator allows XSS
    pom.xml
    A package you depend on has a known security hole (CVE-2019-10219). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages
    pom.xml
    A package you depend on has a known security hole (CVE-2020-10693). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-1932 hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS
    pom.xml
    A package you depend on has a known security hole (CVE-2023-1932). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language Injection
    pom.xml
    A package you depend on has a known security hole (CVE-2025-35036). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-27772 Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot
    pom.xml
    A package you depend on has a known security hole (CVE-2022-27772). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-22235 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
    pom.xml
    A package you depend on has a known security hole (CVE-2025-22235). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-40973 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory
    pom.xml
    A package you depend on has a known security hole (CVE-2026-40973). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS Vulnerability
    pom.xml
    A package you depend on has a known security hole (CVE-2023-20883). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22243 springframework: URL Parsing with Host Validation
    pom.xml
    A package you depend on has a known security hole (CVE-2024-22243). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22259 springframework: URL Parsing with Host Validation
    pom.xml
    A package you depend on has a known security hole (CVE-2024-22259). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22262 springframework: URL Parsing with Host Validation
    pom.xml
    A package you depend on has a known security hole (CVE-2024-22262). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-38809 org.springframework:spring-web: Spring Framework DoS via conditional HTTP request
    pom.xml
    A package you depend on has a known security hole (CVE-2024-38809). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...
    pom.xml
    A package you depend on has a known security hole (CVE-2024-38820). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-5398 springframework: RFD attack via Content-Disposition Header sourced from request input by Spring MVC or Spring WebFlux Application
    pom.xml
    A package you depend on has a known security hole (CVE-2020-5398). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-38819 org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks
    pom.xml
    A package you depend on has a known security hole (CVE-2024-38819). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41842 spring-framework: Spring Framework: Denial of Service when resolving static resources
    pom.xml
    A package you depend on has a known security hole (CVE-2026-41842). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41845 org.springframework: Spring Framework: Cross-site scripting (XSS) via incorrect JavaScript escaping
    pom.xml
    A package you depend on has a known security hole (CVE-2026-41845). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22745 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows
    pom.xml
    A package you depend on has a known security hole (CVE-2026-22745). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41841 Spring MVC and WebFlux applications are vulnerable to Information Disc ...
    pom.xml
    A package you depend on has a known security hole (CVE-2026-41841). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41843 spring-webflux: spring-webmvc: Spring Framework: Information Disclosure via Path Traversal
    pom.xml
    A package you depend on has a known security hole (CVE-2026-41843). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41844 Spring Framework: Spring Framework: Open Redirect via crafted link
    pom.xml
    A package you depend on has a known security hole (CVE-2026-41844). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41846 Spring Framework: Spring Framework: Cross-site scripting (XSS) via user-supplied values in JSP form tags
    pom.xml
    A package you depend on has a known security hole (CVE-2026-41846). Fix: Update that package to its patched version.
… 11 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner timed out

Your dependencies cross-checked against the OSV vulnerability database.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OSV-Scanner v1.9.2 · Apache-2.0

error: timeout after 120s

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.