Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2016-6798 XML External Entity Reference in Apache SlingCVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2025-49128 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocationCVE-2020-25649 jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)CVE-2020-36518 jackson-databind: denial of service via a large depth of nested objectsCVE-2021-46877 jackson-databind: Possible DoS if using JDK serialization to serialize JsonNodeCVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYSCVE-2022-42004 jackson-databind: use of deeply nested arraysCVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypassCVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code executionCVE-2026-50193 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processingCVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS ResolutionCVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modifiedCVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gsonCVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2020-15250 junit4: TemporaryFolder is shared between all users across system which could result in information disclosureCVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIsCVE-2016-5394 Cross site scripting in Apache SlingCVE-2017-15717 Cross-site Scripting in Apache Sling XSS Protection APICVE-2021-37714 jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuckYour dependencies cross-checked against the OSV vulnerability database.
GHSA-7g54-vgp6-jj5w XML External Entity Reference in Apache SlingGHSA-c27h-mcmw-48hv Deserialization of Untrusted Data in org.codehaus.jackson:jackson-mapper-aslGHSA-h46c-h94j-95f3 jackson-core can throw a StackoverflowError when processing deeply nested dataGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-wf8f-6423-gfxg Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocationGHSA-288c-cq4h-88gq XML External Entity (XXE) Injection in Jackson DatabindGHSA-3wrr-7qpf-2prh jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()GHSA-3x8x-79m2-3w2w jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNodeGHSA-57j2-w4cx-62h2 Deeply nested json in jackson-databindGHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesGHSA-hgj6-7826-r7m5 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)GHSA-j3rv-43j4-c7qm jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiationGHSA-jjjh-jjxp-wpff Uncontrolled Resource Consumption in Jackson-databindGHSA-rgv9-q543-rqg4 Uncontrolled Resource Consumption in FasterXML jackson-databindGHSA-rmj7-2vxq-3g9f jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)GHSA-4jrv-ppp4-jm57 Deserialization of Untrusted Data in GsonGHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderGHSA-gwrp-pvrq-jmwv Path Traversal and Improper Input Validation in Apache Commons IOGHSA-qmx3-m648-hr74 Log Injection in Apache Sling Commons Log and Apache Sling APIGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-mvr2-9pj6-7w5j Denial of Service in Google GuavaGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-7r82-7xv7-xcpj Cross-site scripting in Apache HttpClientGHSA-7mfw-43c4-45mq Cross-site Scripting in Apache Sling XSS Protection APICode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.