Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2026-25537 jsonwebtoken: jsonwebtoken has Type Confusion that leads to potential authorization bypassGHSA-36hh-v3qg-5jq4 PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iteratorsGHSA-chgr-c6px-7xpp PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closuresGHSA-4w2j-m93h-cj5j Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassemblyGHSA-82j2-j2ch-gfr8 rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGGHSA-82j2-j2ch-gfr8 rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGGHSA-pwjx-qhcg-rvj4 webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logicGHSA-82j2-j2ch-gfr8 rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGGHSA-7gcf-g7xr-8hxj serde_with: KeyValueMap serialization panics on empty sequence or map entriesGHSA-3pv8-6f4r-ffg2 tar has a PAX header desynchronization issueCVE-2026-44216 wasmtime: Wasmtime: Denial of Service via large WebAssembly table allocationCVE-2026-47261 wasmtime-wasi: Wasmtime: Wasmtime: Access control bypass allows unauthorized file truncation via specific open flags.CVE-2026-13676 fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalizationCVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...CVE-2026-18446 fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authorityCVE-2026-6321 fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policiesCVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handlingCVE-2026-45623 postcss: PostCSS: Information disclosure and denial of service via crafted CSS inputGHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureCVE-2026-41305 postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tagsCVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMappingURLCVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragmentsCVE-2026-45736 ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`GHSA-rhfx-m35p-ff5j `IterMut` violates Stacked Borrows by invalidating internal pointerGHSA-cq8v-f236-94qc Rand is unsound with a custom logger using rand::rng()Your dependencies cross-checked against the OSV vulnerability database.
GHSA-h395-gr6q-cpjc jsonwebtoken has Type Confusion that leads to potential authorization bypassRUSTSEC-2025-0067 `libyml::string::yaml_string_extend` is unsound and unmaintainedRUSTSEC-2026-0187 Stack overflow in lopdf via deeply nested PDF objectsRUSTSEC-2026-0179 Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of serviceRUSTSEC-2026-0180 Panic decoding a malformed `hstore` value allows denial of serviceRUSTSEC-2026-0176 Out-of-bounds read in `nth` / `nth_back` for `PyList` and `PyTuple` iteratorsRUSTSEC-2026-0177 Missing `Sync` bound on `PyCFunction::new_closure` closuresRUSTSEC-2026-0185 Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassemblyRUSTSEC-2026-0104 Reachable panic in certificate revocation list parsingRUSTSEC-2026-0049 CRLs not considered authoritative by Distribution Point due to faulty matching logicRUSTSEC-2026-0104 Reachable panic in certificate revocation list parsingRUSTSEC-2026-0104 Reachable panic in certificate revocation list parsingGHSA-7gcf-g7xr-8hxj serde_with: KeyValueMap serialization panics on empty sequence or map entriesRUSTSEC-2025-0068 serde_yml crate is unsound and unmaintainedRUSTSEC-2026-0178 Panic on a `DataRow` with fewer fields than columns allows denial of serviceRUSTSEC-2025-0111 `tokio-tar` parses PAX extended headers incorrectly, allows file smugglingRUSTSEC-2026-0114 Panic when allocating a table exceeding the size of the host's address spaceRUSTSEC-2026-0149 WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restrictionRUSTSEC-2026-0188 WASI hard links and renames bypass wasmtime-wasi's FilePerms for destinationGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.