Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2025-24813 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTCVE-2026-41293 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validatedCVE-2026-43512 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authenticationCVE-2026-43515 tomcat-coyote: tomcat: Improper Authorization allows security bypassCVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserializationCVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserializationCVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctlyCVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2026-22733 Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpointsCVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2026-22733 Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpointsCVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2024-12798 logback-core: arbitrary code execution via JaninoEventEvaluatorCVE-2025-11226 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-coreCVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypassCVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code executionCVE-2026-50193 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processingCVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS ResolutionCVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modifiedCVE-2026-40984 micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requestsCVE-2023-46589 tomcat: HTTP request smuggling via malformed trailer headersCVE-2024-34750 tomcat: Improper Handling of Exceptional ConditionsYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.