gitsafehub
github.com/ridter/memshellparty ↗

ridter/memshellparty

scanned 2026-08-08 · git 94b6b00
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies77Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 77 found · 5 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2015-7501). Fix: Update that package to its patched version.
  • Serious CVE-2022-42920 Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2022-42920). Fix: Update that package to its patched version.
  • Serious CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2015-7501). Fix: Update that package to its patched version.
  • Serious CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000027). Fix: Update that package to its patched version.
  • Serious CVE-2023-20860 springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2023-20860). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-11226 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2025-11226). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (GHSA-r7wm-3cxj-wff9). Fix: Update that package to its patched version.
  • Worth fixing GHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (GHSA-72hv-8253-57qq). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-54512). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-54513). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-54514). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-54515). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59888 com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-59888). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59889 jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-59889). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mhm7-754m-9p8w jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (GHSA-mhm7-754m-9p8w). Fix: Update that package to its patched version.
  • Worth fixing CVE-2014-0114 1: Class Loader manipulation via request parameters
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2014-0114). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2019-10086). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-48734 commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2025-48734). Fix: Update that package to its patched version.
  • Worth fixing CVE-2015-6420 Insecure Deserialization in Apache Commons Collection
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2015-6420). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-24970 io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2025-24970). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44249 netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-44249). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45416 netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-45416). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-50010 netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-50010). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45674 netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-45674). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-47691 io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
    examples/memshell-party-maven-example/pom.xml
    A package you depend on has a known security hole (CVE-2026-47691). Fix: Update that package to its patched version.
… 52 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner timed out

Your dependencies cross-checked against the OSV vulnerability database.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OSV-Scanner v1.9.2 · Apache-2.0

error: timeout after 120s

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.