Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-1597 pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLECVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYSCVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypassCVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code executionCVE-2026-50193 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processingCVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS ResolutionCVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modifiedCVE-2026-2332 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsingCVE-2023-40167 jetty: Improper validation of HTTP/1 content-lengthCVE-2024-6763 org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authorityCVE-2026-10050 In Eclipse Jetty, the Digest authentication server-side component uses ...CVE-2024-7708 Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requestsCVE-2023-26048 jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()CVE-2024-8184 org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksCVE-2026-6790 In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no ...CVE-2022-31197 postgresql: SQL Injection in ResultSet.refreshRow() with malicious column namesCVE-2026-42198 jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authenticationCVE-2022-41946 postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissionsCVE-2025-11143 org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsingCVE-2023-26049 jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookiesGHSA-58qw-p7qm-5rvh Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarationsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-24rp-q3w6-vc56 org.postgresql:postgresql vulnerable to SQL Injection via line comment generationGHSA-3wrr-7qpf-2prh jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()GHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesGHSA-hgj6-7826-r7m5 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)GHSA-j3rv-43j4-c7qm jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiationGHSA-jjjh-jjxp-wpff Uncontrolled Resource Consumption in Jackson-databindGHSA-rmj7-2vxq-3g9f jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)GHSA-562r-vg33-8x8h TemporaryFolder on unix-like systems does not limit access to created filesGHSA-98qh-xjc8-98pq pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoSGHSA-r38f-c4h4-hqq2 PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column namesGHSA-h46c-h94j-95f3 jackson-core can throw a StackoverflowError when processing deeply nested dataGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingGHSA-hmr7-m48g-48f6 Jetty accepts "+" prefixed value in Content-LengthGHSA-qh8g-58pp-2wxh Eclipse Jetty URI parsing of invalid authorityGHSA-2fvj-hgj9-j2gr Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitutionGHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatchGHSA-9299-c6m4-mjhc Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requestsGHSA-g8m5-722r-8whq Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksGHSA-qw69-rqj8-6qw8 OutOfMemoryError for large multipart without filename in Eclipse JettyGHSA-wjpw-4j6x-6rwh org.eclipse.jetty:jetty-http has different parsing of invalid URIsGHSA-p26g-97m4-6q7c Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookiesGHSA-58qw-p7qm-5rvh Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarationsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.