Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code executionCVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfigCVE-2019-16335 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSourceCVE-2019-16942 jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.*CVE-2019-16943 jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSourceCVE-2019-17267 jackson-databind: Serialization gadgets in classes of the ehcache packageCVE-2019-17531 jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.*CVE-2019-20330 jackson-databind: lacks certain net.sf.ehcache blockingCVE-2020-8840 jackson-databind: Lacks certain xbean-reflect/JNDI blockingCVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-configCVE-2020-9547 jackson-databind: Serialization gadgets in ibatis-sqlmapCVE-2020-9548 jackson-databind: Serialization gadgets in anteros-coreCVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2025-49128 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocationCVE-2019-14439 jackson-databind: Polymorphic typing issue related to logback/JNDICVE-2019-14892 jackson-databind: Serialization gadgets in classes of the commons-configuration packageCVE-2019-14893 jackson-databind: Serialization gadgets in classes of the xalan packageCVE-2020-10650 A deserialization flaw was discovered in jackson-databind through 2.9. ...CVE-2020-10672 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command executionCVE-2020-10673 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command executionCVE-2020-10968 jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProviderCVE-2020-10969 jackson-databind: Serialization gadgets in javax.swing.JEditorPaneCVE-2020-11111 jackson-databind: Serialization gadgets in org.apache.activemq.jms.pool.XaPooledConnectionFactoryCVE-2020-11112 jackson-databind: Serialization gadgets in org.apache.commons.proxy.provider.remoting.RmiProviderYour dependencies cross-checked against the OSV vulnerability database.
GHSA-4w82-r329-3q67 Deserialization of Untrusted Data in jackson-databindGHSA-5p34-5m6p-p58g jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-6fpp-rgj9-8rwc Deserialization of untrusted data in FasterXML jackson-databindGHSA-85cw-hj65-qqv9 Polymorphic Typing issue in FasterXML jackson-databindGHSA-f3j5-rmmp-3fc5 Improper Input Validation in jackson-databindGHSA-fmmc-742q-jg75 jackson-databind polymorphic typing issueGHSA-gjmw-vf9h-g25v jackson-databind polymorphic typing issueGHSA-gww7-p5w4-wrfv Deserialization of Untrusted Data in jackson-databindGHSA-h822-r4r5-v8jg Polymorphic Typing issue in FasterXML jackson-databindGHSA-mx7p-6679-8g3q Polymorphic Typing in FasterXML jackson-databindGHSA-p43x-xfjf-5jhr jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-q93h-jc49-78gg jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-27xj-rqx5-2255 jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-288c-cq4h-88gq XML External Entity (XXE) Injection in Jackson DatabindGHSA-57j2-w4cx-62h2 Deeply nested json in jackson-databindGHSA-58pp-9c76-5625 jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-5949-rw7g-wx7w Deserialization of untrusted data in jackson-databindGHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesGHSA-5r5r-6hpj-8gg9 Serialization gadget exploit in jackson-databindGHSA-758m-v56v-grj4 jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-89qr-369f-5m5x Unsafe Deserialization in jackson-databindGHSA-8c4j-34r4-xr8g Unsafe Deserialization in jackson-databindGHSA-8w26-6f25-cm9x Unsafe Deserialization in jackson-databindGHSA-95cm-88f5-f2c7 jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-9gph-22xh-8x98 Unsafe Deserialization in jackson-databindCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.