Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2019-10212 undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log filesCVE-2019-3888 undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailedCVE-2022-4492 undertow: Server identity in https connection is not checked by the undertow clientCVE-2025-12543 undertow-core: Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRFCVE-2017-12165 undertow: improper whitespace parsing leading to potential HTTP request smugglingCVE-2019-14888 undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPSCVE-2020-10705 undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" headerCVE-2020-1745 undertow: AJP File Read/Inclusion VulnerabilityCVE-2020-1757 undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypassCVE-2020-27782 undertow: special character in query results in server errorsCVE-2021-3629 undertow: potential security issue in flow control over HTTP/2 may lead to DOSCVE-2021-3690 undertow: buffer leak on incoming websocket PONG message may lead to DoSCVE-2021-3859 undertow: client side invocation timeout raised when calling over HTTP2CVE-2022-2053 undertow: Large AJP request may cause DoSCVE-2023-1108 Undertow: Infinite loop in SslConduit during closeCVE-2023-4639 undertow: Cookie Smuggling/SpoofingCVE-2024-1635 undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocolCVE-2024-3884 undertow: OutOfMemory when parsing form data encoding with application/x-www-form-urlencodedCVE-2024-4027 undertow: OutOfMemoryError in HttpServletRequestImpl.getParameterNames() can cause remote DoS attacksCVE-2024-5971 undertow: response write hangs in case of Java 17 TLSv1.3 NewSessionTicketCVE-2024-6162 undertow: url-encoded request path information can be broken on ajp-listenerCVE-2024-7885 undertow: Improper State Management in Proxy Protocol parsing causes information leakageCVE-2025-9784 undertow: Undertow MadeYouReset HTTP/2 DDoS VulnerabilityCVE-2016-7046 undertow: Long URL proxy request lead to java.nio.BufferOverflowException and DoSCVE-2017-12196 undertow: Client can use bogus uri in Digest authenticationYour dependencies cross-checked against the OSV vulnerability database.
GHSA-8vh8-vc28-m2hf Potential to access user credentials from the log files when debug logging enabledGHSA-j382-5jj3-vw4j Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requestsGHSA-jwgx-9mmh-684w Credential exposure through log files in UndertowGHSA-pfcc-3g6r-8rg8 Undertow client not checking server identity presented by server certificate in https connectionsGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-2w73-fqqj-c92p Improper Input Validation in UndertowGHSA-339q-62wm-c39w Undertow vulnerable to Denial of Service (DoS) attacksGHSA-33hj-rcmx-86mv Undertow Servlets Vulnerable to Remote DoS via OutOfMemoryError when Passed Large Parameter NamesGHSA-3f57-w2rp-72fc Undertow Uncaught Exception vulnerabilityGHSA-3jrv-jgp8-45v3 Undertow incorrectly parses cookiesGHSA-3x3v-w654-m28m Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET RequestsGHSA-5gg7-5wv8-4gcj Undertow Request Smuggling vulnerabilityGHSA-6h4f-pj3g-q8fq Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencodedGHSA-9442-gm4v-r222 Undertow's url-encoded request path information can be broken on ajp-listenerGHSA-95h4-w6j8-2rp8 Undertow MadeYouReset HTTP/2 DDoS VulnerabilityGHSA-95rf-557x-44g5 Undertow vulnerable to Dos via Large AJP requestGHSA-9623-mqmm-5rcf Undertow vulnerable to Race ConditionGHSA-97cq-f4jm-mv8h Undertow Denial of Service vulnerabilityGHSA-cccf-7xw3-p2vr HTTP Request Smuggling in UndertowGHSA-ch7q-gpff-h9hp Undertow Missing Release of Memory after Effective Lifetime vulnerabilityGHSA-cp7v-vmv7-6x2q Incorrect Authorization in UndertowGHSA-fj7c-vg2v-ccrm Undertow vulnerable to memory exhaustion due to buffer leakGHSA-g4cp-h53p-v3v8 Allocation of Resources Without Limits or Throttling in UndertowGHSA-gjjx-gqm4-wcgm Uncontrolled Resource Consumption in UndertowGHSA-gv2w-88hx-8m9r Improper Authorization in UndertoeCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.