Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-46600 golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsingCVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 inputGHSA-gcjh-h69q-9w9g cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTagCVE-2026-2303 CVE-2026-2303 affecting package telegraf for versions less than 1.29.4-21CVE-2026-46600 golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsingCVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 inputCVE-2026-34040 Moby: Moby: Authorization bypass vulnerabilityCVE-2026-33997 moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installationCVE-2026-40611 github.com/go-acme/lego: Lego: Arbitrary file write and deletion via path traversal from a malicious ACME serverGHSA-gcjh-h69q-9w9g cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTagCVE-2026-35469 Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming codeCVE-2026-2303 CVE-2026-2303 affecting package telegraf for versions less than 1.29.4-21CVE-2026-29181 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headersCVE-2026-24051 opentelemetry-go: OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH HijackingCVE-2026-39883 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/SolarisCVE-2026-46600 golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsingCVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 inputGHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 VulnerabilitiesCVE-2025-8556 github.com/cloudflare/circl: CIRCL-Fourq: Missing and wrong validation can lead to incorrect resultsCVE-2026-1229 CIRCL has an incorrect calculation in secp384r1 CombinedMultCVE-2025-54799 github.com/go-acme/lego: Lego: Unenforced HTTPS Communication VulnerabilityCVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content no ...CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb ...CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content no ...Your dependencies cross-checked against the OSV vulnerability database.
GO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGHSA-gcjh-h69q-9w9g cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTagGO-2026-5327 Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driverGO-2026-4883 Moby has an Off-by-one error in its plugin privilege validation in github.com/docker/dockerGO-2026-4887 Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/dockerGO-2026-5617 Race condition in 'docker cp' in github.com/docker/docker allows bind mount redirectionGO-2026-5668 Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary filesGO-2026-5746 Docker: 'PUT /containers/{id}/archive' executes container binary on the host in github.com/docker/dockerGO-2026-5593 ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider in github.com/go-acme/legoGHSA-gcjh-h69q-9w9g cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTagGO-2026-4958 Uncontrolled resource consumption when parsing SPDY frames in github.com/moby/spdystreamGO-2026-5327 Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driverGO-2026-5506 OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otelGO-2026-4394 OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking in go.opentelemetry.io/otel/sdkGO-2026-5426 Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdkGO-2026-6061 Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpcGO-2025-3754 CIRCL-Fourq: Missing and wrong validation can lead to incorrect results in github.com/cloudflare/circlGO-2026-4550 CIRCL has an incorrect calculation in secp384r1 CombinedMult in github.com/cloudflare/circlGO-2025-3847 Github.com/go-acme/lego/v4/acme/api does not enforce HTTPS in github.com/go-acme/legoGO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessageGO-2026-5970 Infinite loop on invalid input in golang.org/x/textGO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaGO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessageGO-2026-5972 Enforce maximum recursion depth in encoding/asn1GO-2026-6088 Add recursion depth guard during decode in encoding/xmlCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.