Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket framesCVE-2026-1526 undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompressionCVE-2026-2229 undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameterCVE-2026-15157 undici: undici: HTTP header injection via unvalidated blob-like body type propertyCVE-2026-1525 undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headersCVE-2026-1527 undici: Undici: HTTP header injection and request smuggling vulnerabilityCVE-2026-16728 undici: undici: Response desynchronization via retry interceptor with mismatched Content-LengthCVE-2026-16729 undici: Undici: Cookie attribute injection allows bypassing security protectionsCVE-2026-22036 undici: Undici: Denial of Service via excessive decompression stepsCVE-2026-9679 undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decodingCVE-2025-47279 undici: Undici Memory Leak with Invalid CertificatesCVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie headerCVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.Your dependencies cross-checked against the OSV vulnerability database.
GHSA-2mjp-6q6p-2qxm Undici has an HTTP Request/Response Smuggling issueGHSA-4992-7rv2-5pvq Undici has CRLF Injection in undici via `upgrade` optionGHSA-8xcm-r25x-g524 undici vulnerable to downstream response desynchronization via retry interceptorGHSA-g9mf-h72j-4rw9 Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustionGHSA-m8rv-5g2x-5cg5 undici vulnerable to CRLF Injection via blob-like body 'type' propertyGHSA-p88m-4jfj-68fv undici vulnerable to HTTP header injection via Set-Cookie percent-decodingGHSA-v3r7-h72x-cjcm undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fieldsGHSA-v9p9-hfj2-hcw8 Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits ValidationGHSA-vrm6-8vpv-qv8q Undici has Unbounded Memory Consumption in WebSocket permessage-deflate DecompressionGHSA-vxpw-j846-p89q undici WebSocket client vulnerable to denial of service via fragment count bypassGHSA-35p6-xmwp-9g52 undici vulnerable to HTTP response queue poisoning via keep-alive socket reuseGHSA-cxrh-j4jr-qwg3 undici Denial of Service attack via bad certificate dataGHSA-g8m3-5g58-fq7m undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matchingCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.