gitsafehub
github.com/saturnism/quarkus-balloons ↗

saturnism/quarkus-balloons

scanned 2026-08-12 · git 57706bb
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies180Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 180 found · 14 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2015-8857 The uglify-js package before 2.4.24 for Node.js does not properly acco ...
    balloon-game-mobile/node_modules/ember-cli/node_modules/underscore.string/Gemfile.lock
    A package you depend on has a known security hole (CVE-2015-8857). Fix: Update that package to its patched version.
  • Serious CVE-2020-26238 cron-utils: template injection allows attackers to inject arbitrary Java EL expressions leading to remote code execution
    balloon-game-server/pom.xml
    A package you depend on has a known security hole (CVE-2020-26238). Fix: Update that package to its patched version.
  • Serious CVE-2021-41269 cron-utils: template Injection leading to unauthenticated Remote Code Execution
    balloon-game-server/pom.xml
    A package you depend on has a known security hole (CVE-2021-41269). Fix: Update that package to its patched version.
  • Serious CVE-2019-17640 Path Traversal in Eclipse Vert
    balloon-pop-stream-basic/pom.xml
    A package you depend on has a known security hole (CVE-2019-17640). Fix: Update that package to its patched version.
  • Serious CVE-2019-17640 Path Traversal in Eclipse Vert
    configuration-service-q/pom.xml
    A package you depend on has a known security hole (CVE-2019-17640). Fix: Update that package to its patched version.
  • Serious CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2020-1938). Fix: Update that package to its patched version.
  • Serious CVE-2025-24813 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2025-24813). Fix: Update that package to its patched version.
  • Serious CVE-2026-41293 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2026-41293). Fix: Update that package to its patched version.
  • Serious CVE-2026-43512 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2026-43512). Fix: Update that package to its patched version.
  • Serious CVE-2026-43515 tomcat-coyote: tomcat: Improper Authorization allows security bypass
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2026-43515). Fix: Update that package to its patched version.
  • Serious CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
  • Serious CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
  • Serious CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000027). Fix: Update that package to its patched version.
  • Serious CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+
    configuration-service-sb/pom.xml
    A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-8130 rake: OS Command Injection via egrep in Rake::FileList
    balloon-game-mobile/node_modules/ember-cli/node_modules/underscore.string/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-8130). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-66035 angular: Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2025-66035). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-50170 @angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2026-50170). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-50171 @angular/common: Angular @angular/common: Denial of Service via malformed digitsInfo parameter
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2026-50171). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54266 @angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2026-54266). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54268 @angular/common: Angular @angular/common: Denial of Service via crafted date format string
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2026-54268). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-68945 @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2026-68945). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-66412 angular: Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2025-66412). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22610 angular: Angular: Cross-site scripting vulnerability in Template Compiler
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2026-22610). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-69151 @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2026-69151). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-50557 @angular/compiler: @angular/core: Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
    balloon-game-mobile/package-lock.json
    A package you depend on has a known security hole (CVE-2026-50557). Fix: Update that package to its patched version.
… 155 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner timed out

Your dependencies cross-checked against the OSV vulnerability database.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OSV-Scanner v1.9.2 · Apache-2.0

error: timeout after 120s

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.