gitsafehub
github.com/matthewd/jruby ↗

matthewd/jruby

scanned 2026-08-07 · git a8807f2
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies54Known OSS vulnerabilities81Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 54 found · 2 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2022-24790 puma-5.6.4: http request smuggling vulnerabilities
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-24790). Fix: Update that package to its patched version.
  • Serious CVE-2022-30123 rubygem-rack: crafted requests can cause shell escape sequences
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-30123). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-8130 rake: OS Command Injection via egrep in Rake::FileList
    maven/jruby-complete/src/it/runnable/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-8130). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-16770 rubygem-puma: keepalive requests from poorly-behaved client leads to denial of service
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2019-16770). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-11076 rubygem-puma: HTTP Smuggling via an invalid Transfer-Encoding Header
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-11076). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-29509 rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS)
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2021-29509). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-23634 rubygem-puma: rubygem-rails: information leak between requests
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-23634). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-11077 rubygem-puma: HTTP Smuggling through a proxy via Transfer-Encoding Header
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-11077). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-5247 rubygem-puma: attacker is able to use newline characters to insert malicious content (HTTP Response Splitting), this could lead to XSS
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-5247). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-5249 rubygem-puma: attacker is able to use carriage return character to insert malicious content (HTTP Response Splitting), this could lead to XSS
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-5249). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-40175 rubygem-puma: HTTP request smuggling when parsing chunked transfer encoding bodies and zero-length content-length headers
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2023-40175). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-21647 rubygem-puma: HTTP request smuggling when parsing chunked Transfer-Encoding Bodies
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2024-21647). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-45614 rubygem-puma: Header normalization allows for client to clobber proxy set headers
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2024-45614). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-8161 rubygem-rack: directory traversal in Rack::Directory
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-8161). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-8184 rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-8184). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-30122 rubygem-rack: crafted multipart POST request may cause a DoS
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-30122). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-44570 rubygem-rack: denial of service in Content-Disposition parsing
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-44570). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-44571 rubygem-rack: denial of service in Content-Disposition parsing
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-44571). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-44572 rubygem-rack: denial of service in Content-Disposition parsing
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-44572). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-27530 rubygem-rack: Denial of service in Multipart MIME parsing
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2023-27530). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-26141 rubygem-rack: Possible DoS Vulnerability with Range Header in Rack
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2024-26141). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-26146 rubygem-rack: Possible Denial of Service Vulnerability in Rack Header Parsing
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2024-26146). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27111 rack: rubygem-rack: Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2025-27111). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27610 rack: rubygem-rack: Local File Inclusion in Rack::Static
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2025-27610). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-46727 rubygem-rack: Unbounded-Parameter DoS in Rack::QueryParser
    maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2025-46727). Fix: Update that package to its patched version.
… 29 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 81 found · 3 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-68xg-gqqm-vgj8 Puma HTTP Request/Response Smuggling vulnerability
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2023-40175). Fix: Update that package to its patched version.
  • Serious GHSA-h99w-9q5r-gjq9 Puma vulnerable to HTTP Request Smuggling
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-24790). Fix: Update that package to its patched version.
  • Serious GHSA-wq4h-7r42-5hrr Possible shell escape sequence injection vulnerability in Rack
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/templates/hellowarld/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-30123). Fix: Update that package to its patched version.
  • Worth fixing GHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created files
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/core/pom.xml
    A package you depend on has a known security hole (CVE-2020-15250). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4p6w-m9wc-c9c9 Sensitive Data Exposure in Apache Ant
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/core/pom.xml
    A package you depend on has a known security hole (CVE-2020-1945). Fix: Update that package to its patched version.
  • Worth fixing GHSA-5v34-g2px-j4fw Improper Handling of Length Parameter Inconsistency in Apache Ant
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/core/pom.xml
    A package you depend on has a known security hole (CVE-2021-36374). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f62v-xpxf-3v68 Code injection in Apache Ant
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/core/pom.xml
    A package you depend on has a known security hole (CVE-2020-11979). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q5r4-cfpx-h6fh Improper Handling of Length Parameter Inconsistency in Apache Ant
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/core/pom.xml
    A package you depend on has a known security hole (CVE-2021-36373). Fix: Update that package to its patched version.
  • Worth fixing GHSA-jppv-gw3r-w3q8 OS Command Injection in Rake
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby-complete/src/it/runnable/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-8130). Fix: Update that package to its patched version.
  • Worth fixing GHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created files
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2020-15250). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4cx2-fc23-5wg6 Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2025-8916). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wg6q-6289-32hp Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2026-5588). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2j2x-hx4g-2gf4 In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000344). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4vhj-98r6-424h In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000338). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6xx3-rg99-gc3p Timing based private key exposure in Bouncy Castle
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2020-15522). Fix: Update that package to its patched version.
  • Worth fixing GHSA-72m5-fvvv-55m6 Observable Differences in Behavior to Error Inputs in Bouncy Castle
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2020-26939). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8xfc-gm6g-vgpv Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2024-29857). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9gp4-qrff-c648 Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000345). Fix: Update that package to its patched version.
  • Worth fixing GHSA-c8xf-m4ff-jcxj Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000339). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hr8g-6v94-x4m9 Bouncy Castle For Java LDAP injection vulnerability
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2023-33201). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qcj7-g2j5-g7r3 In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verification
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000342). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r97x-3g8f-gx3m The Bouncy Castle JCE Provider carry a propagation bug
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000340). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r9ch-m4fh-fc7q Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000341). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rrvx-pwf8-p59p In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000343). Fix: Update that package to its patched version.
  • Worth fixing GHSA-v435-xc8x-wvr9 Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
    /workdirs/scan-ea58f3eb-2500-479a-b585-17e6c9e7a903/maven/jruby/src/it/bouncycastle/pom.xml
    A package you depend on has a known security hole (CVE-2024-30171). Fix: Update that package to its patched version.
… 56 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.