📦 Vulnerable dependencies — Trivyⓘ3 found · 1 serious
Packages you depend on that have known security holes (CVEs).
SeriousGHSA-r277-6w6q-xmqw kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
go.mod
A package you depend on has a known security hole (GHSA-r277-6w6q-xmqw). Fix: Update that package to its patched version.
Worth fixingGHSA-jpcw-4wr7-c3vq kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
go.mod
A package you depend on has a known security hole (GHSA-jpcw-4wr7-c3vq). Fix: Update that package to its patched version.
Worth fixingCVE-2026-56852 A norm.Iter can enter an infinite loop when handling input containing ...
go.mod
A package you depend on has a known security hole (CVE-2026-56852). Fix: Update that package to its patched version.
A package you depend on has a known security hole. Fix: Update that package to its patched version.
Worth fixingGHSA-jpcw-4wr7-c3vq kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.