gitsafehub
github.com/marcossancal/backend_javalin ↗

marcossancal/backend_javalin

scanned 2026-08-05 · git 81217b9
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies23Known OSS vulnerabilities23Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 23 found · 1 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2024-1597 pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE
    pom.xml
    A package you depend on has a known security hole (CVE-2024-1597). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError
    pom.xml
    A package you depend on has a known security hole (CVE-2025-52999). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
    pom.xml
    A package you depend on has a known security hole (GHSA-r7wm-3cxj-wff9). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS
    pom.xml
    A package you depend on has a known security hole (CVE-2022-42003). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
    pom.xml
    A package you depend on has a known security hole (CVE-2026-54512). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
    pom.xml
    A package you depend on has a known security hole (CVE-2026-54513). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-50193 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing
    pom.xml
    A package you depend on has a known security hole (CVE-2026-50193). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
    pom.xml
    A package you depend on has a known security hole (CVE-2026-54514). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
    pom.xml
    A package you depend on has a known security hole (CVE-2026-54515). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-2332 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
    pom.xml
    A package you depend on has a known security hole (CVE-2026-2332). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-40167 jetty: Improper validation of HTTP/1 content-length
    pom.xml
    A package you depend on has a known security hole (CVE-2023-40167). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6763 org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
    pom.xml
    A package you depend on has a known security hole (CVE-2024-6763). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-10050 In Eclipse Jetty, the Digest authentication server-side component uses ...
    pom.xml
    A package you depend on has a known security hole (CVE-2026-10050). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-7708 Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
    pom.xml
    A package you depend on has a known security hole (CVE-2024-7708). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-26048 jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
    pom.xml
    A package you depend on has a known security hole (CVE-2023-26048). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-8184 org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
    pom.xml
    A package you depend on has a known security hole (CVE-2024-8184). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-6790 In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no ...
    pom.xml
    A package you depend on has a known security hole (CVE-2026-6790). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-31197 postgresql: SQL Injection in ResultSet.refreshRow() with malicious column names
    pom.xml
    A package you depend on has a known security hole (CVE-2022-31197). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42198 jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
    pom.xml
    A package you depend on has a known security hole (CVE-2026-42198). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-41946 postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions
    pom.xml
    A package you depend on has a known security hole (CVE-2022-41946). Fix: Update that package to its patched version.
  • Minor CVE-2025-11143 org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
    pom.xml
    A package you depend on has a known security hole (CVE-2025-11143). Fix: Update that package to its patched version.
  • Minor CVE-2023-26049 jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
    pom.xml
    A package you depend on has a known security hole (CVE-2023-26049). Fix: Update that package to its patched version.
  • Minor GHSA-58qw-p7qm-5rvh Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
    pom.xml
    A package you depend on has a known security hole (GHSA-58qw-p7qm-5rvh). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 23 found · 1 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-24rp-q3w6-vc56 org.postgresql:postgresql vulnerable to SQL Injection via line comment generation
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2024-1597). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3wrr-7qpf-2prh jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-50193). Fix: Update that package to its patched version.
  • Worth fixing GHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-54515). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hgj6-7826-r7m5 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-54514). Fix: Update that package to its patched version.
  • Worth fixing GHSA-j3rv-43j4-c7qm jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-54512). Fix: Update that package to its patched version.
  • Worth fixing GHSA-jjjh-jjxp-wpff Uncontrolled Resource Consumption in Jackson-databind
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2022-42003). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rmj7-2vxq-3g9f jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-54513). Fix: Update that package to its patched version.
  • Worth fixing GHSA-562r-vg33-8x8h TemporaryFolder on unix-like systems does not limit access to created files
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2022-41946). Fix: Update that package to its patched version.
  • Worth fixing GHSA-98qh-xjc8-98pq pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-42198). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r38f-c4h4-hqq2 PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2022-31197). Fix: Update that package to its patched version.
  • Worth fixing GHSA-h46c-h94j-95f3 jackson-core can throw a StackoverflowError when processing deeply nested data
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2025-52999). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-2332). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hmr7-m48g-48f6 Jetty accepts "+" prefixed value in Content-Length
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2023-40167). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qh8g-58pp-2wxh Eclipse Jetty URI parsing of invalid authority
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2024-6763). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2fvj-hgj9-j2gr Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-10050). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatch
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2026-6790). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9299-c6m4-mjhc Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2024-7708). Fix: Update that package to its patched version.
  • Worth fixing GHSA-g8m5-722r-8whq Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2024-8184). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qw69-rqj8-6qw8 OutOfMemoryError for large multipart without filename in Eclipse Jetty
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2023-26048). Fix: Update that package to its patched version.
  • Minor GHSA-wjpw-4j6x-6rwh org.eclipse.jetty:jetty-http has different parsing of invalid URIs
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2025-11143). Fix: Update that package to its patched version.
  • Minor GHSA-p26g-97m4-6q7c Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole (CVE-2023-26049). Fix: Update that package to its patched version.
  • Minor GHSA-58qw-p7qm-5rvh Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
    /workdirs/scan-a03334cd-de80-472a-9c53-59ac1608b18d/pom.xml
    A package you depend on has a known security hole. Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.