Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2022-24790 puma-5.6.4: http request smuggling vulnerabilitiesCVE-2022-30123 rubygem-rack: crafted requests can cause shell escape sequencesCVE-2020-8130 rake: OS Command Injection via egrep in Rake::FileListCVE-2019-16770 rubygem-puma: keepalive requests from poorly-behaved client leads to denial of serviceCVE-2020-11076 rubygem-puma: HTTP Smuggling via an invalid Transfer-Encoding HeaderCVE-2021-29509 rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS)CVE-2022-23634 rubygem-puma: rubygem-rails: information leak between requestsCVE-2020-11077 rubygem-puma: HTTP Smuggling through a proxy via Transfer-Encoding HeaderCVE-2020-5247 rubygem-puma: attacker is able to use newline characters to insert malicious content (HTTP Response Splitting), this could lead to XSSCVE-2020-5249 rubygem-puma: attacker is able to use carriage return character to insert malicious content (HTTP Response Splitting), this could lead to XSSCVE-2023-40175 rubygem-puma: HTTP request smuggling when parsing chunked transfer encoding bodies and zero-length content-length headersCVE-2024-21647 rubygem-puma: HTTP request smuggling when parsing chunked Transfer-Encoding BodiesCVE-2024-45614 rubygem-puma: Header normalization allows for client to clobber proxy set headersCVE-2020-8161 rubygem-rack: directory traversal in Rack::DirectoryCVE-2020-8184 rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie namesCVE-2022-30122 rubygem-rack: crafted multipart POST request may cause a DoSCVE-2022-44570 rubygem-rack: denial of service in Content-Disposition parsingCVE-2022-44571 rubygem-rack: denial of service in Content-Disposition parsingCVE-2022-44572 rubygem-rack: denial of service in Content-Disposition parsingCVE-2023-27530 rubygem-rack: Denial of service in Multipart MIME parsingCVE-2024-26141 rubygem-rack: Possible DoS Vulnerability with Range Header in RackCVE-2024-26146 rubygem-rack: Possible Denial of Service Vulnerability in Rack Header ParsingCVE-2025-27111 rack: rubygem-rack: Escape Sequence Injection vulnerability in Rack lead to Possible Log InjectionCVE-2025-27610 rack: rubygem-rack: Local File Inclusion in Rack::StaticCVE-2025-46727 rubygem-rack: Unbounded-Parameter DoS in Rack::QueryParserYour dependencies cross-checked against the OSV vulnerability database.
GHSA-68xg-gqqm-vgj8 Puma HTTP Request/Response Smuggling vulnerabilityGHSA-h99w-9q5r-gjq9 Puma vulnerable to HTTP Request SmugglingGHSA-wq4h-7r42-5hrr Possible shell escape sequence injection vulnerability in RackGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-4p6w-m9wc-c9c9 Sensitive Data Exposure in Apache AntGHSA-5v34-g2px-j4fw Improper Handling of Length Parameter Inconsistency in Apache AntGHSA-f62v-xpxf-3v68 Code injection in Apache AntGHSA-q5r4-cfpx-h6fh Improper Handling of Length Parameter Inconsistency in Apache AntGHSA-jppv-gw3r-w3q8 OS Command Injection in RakeGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-4cx2-fc23-5wg6 Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive AllocationGHSA-wg6q-6289-32hp Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modulesGHSA-2j2x-hx4g-2gf4 In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB modeGHSA-4vhj-98r6-424h In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validateGHSA-6xx3-rg99-gc3p Timing based private key exposure in Bouncy CastleGHSA-72m5-fvvv-55m6 Observable Differences in Behavior to Error Inputs in Bouncy CastleGHSA-8xfc-gm6g-vgpv Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.GHSA-9gp4-qrff-c648 Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15GHSA-c8xf-m4ff-jcxj Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15GHSA-hr8g-6v94-x4m9 Bouncy Castle For Java LDAP injection vulnerabilityGHSA-qcj7-g2j5-g7r3 In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verificationGHSA-r97x-3g8f-gx3m The Bouncy Castle JCE Provider carry a propagation bugGHSA-r9ch-m4fh-fc7q Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15GHSA-rrvx-pwf8-p59p In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default valuesGHSA-v435-xc8x-wvr9 Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.