Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2020-15250 junit4: TemporaryFolder is shared between all users across system which could result in information disclosureCVE-2023-39410 apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDKCVE-2025-27819 org.apache.kafka: Kafka JNDI Login Module RCE VulnerabilityCVE-2020-15250 junit4: TemporaryFolder is shared between all users across system which could result in information disclosureCVE-2020-15250 junit4: TemporaryFolder is shared between all users across system which could result in information disclosureCVE-2020-15250 junit4: TemporaryFolder is shared between all users across system which could result in information disclosureCVE-2023-39410 apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDKCVE-2025-27819 org.apache.kafka: Kafka JNDI Login Module RCE VulnerabilityCVE-2020-15250 junit4: TemporaryFolder is shared between all users across system which could result in information disclosureYour dependencies cross-checked against the OSV vulnerability database.
GHSA-r7pg-v2c8-mfg3 Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)GHSA-4gq5-ch57-c2mg Arbitrary Code Execution in jackson-databindGHSA-4w82-r329-3q67 Deserialization of Untrusted Data in jackson-databindGHSA-645p-88qh-w398 Arbitrary Code Execution in jackson-databindGHSA-6fpp-rgj9-8rwc Deserialization of untrusted data in FasterXML jackson-databindGHSA-85cw-hj65-qqv9 Polymorphic Typing issue in FasterXML jackson-databindGHSA-c8hm-7hpq-7jhg com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted DataGHSA-cggj-fvv3-cqwv FasterXML jackson-databind allows unauthenticated remote code execution GHSA-f3j5-rmmp-3fc5 Improper Input Validation in jackson-databindGHSA-fmmc-742q-jg75 jackson-databind polymorphic typing issueGHSA-gjmw-vf9h-g25v jackson-databind polymorphic typing issueGHSA-gww7-p5w4-wrfv Deserialization of Untrusted Data in jackson-databindGHSA-h592-38cm-4ggp jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code executionGHSA-h822-r4r5-v8jg Polymorphic Typing issue in FasterXML jackson-databindGHSA-mx7p-6679-8g3q Polymorphic Typing in FasterXML jackson-databindGHSA-p43x-xfjf-5jhr jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-q93h-jc49-78gg jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-qr7j-h6gg-jmgc Deserialization of Untrusted Data in jackson-databindGHSA-qxxx-2pp7-5hmx jackson-databind is vulnerable to a deserialization flawGHSA-rfx6-vp9g-rh7v jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypassGHSA-cqqj-4p63-rrmm HTTP Request Smuggling in NettyGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.