Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-1135 python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headersCVE-2024-6827 gunicorn: HTTP Request Smuggling in benoitc/gunicornCVE-2022-35920 sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLsGHSA-7p79-6x2v-5h88 Server crash if running Python 3.10 w/ Sanic 20.12CVE-2022-31116 python-ujson: improper decoding of escaped surrogate characters may lead to string corruption, key confusion or value overwritingCVE-2026-44660 python-ujson: UltraJSON: Memory leak leading to Denial of ServiceCVE-2021-45958 UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow ...CVE-2022-31117 python-ujson: Potential double free of buffer during string decodingCVE-2026-54911 UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()CVE-2018-1000518 websockets is vulnerable to denial of service by memory exhaustionCVE-2021-33880 The aaugustin websockets library before 9.1 for Python has an Observab ...Your dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-1433 Gunicorn HTTP Request/Response Smuggling vulnerabilityPYSEC-2026-1434 Request smuggling leading to endpoint restriction bypass in GunicornPYSEC-2026-918 sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLsGHSA-7p79-6x2v-5h88 Server crash if running Python 3.10 w/ Sanic 20.12PYSEC-2026-1056 Potential double free of buffer during string decodingPYSEC-2026-1057 Incorrect handling of invalid surrogate pair charactersPYSEC-2026-2293 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exceptioPYSEC-2026-2294 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When GHSA-fh56-85cw-5pq6 UltraJSON vulnerable to Out-of-bounds WritePYSEC-2018-79 aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that cPYSEC-2021-95 The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An aPYSEC-2026-2291 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the raPYSEC-2026-2292 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handlPYSEC-2026-2293 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exceptioPYSEC-2026-2294 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When OSV-2021-955 Stack-buffer-overflow in Buffer_AppendIndentUncheckedCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.