Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
CVE-2025-44005 github.com/smallstep/certificates: github.com/smallstep/certificates: Authorization bypass allows unauthorized certificate creationCVE-2026-30836 github.com/smallstep/certificates: Step CA: Unauthenticated certificate issuance via SCEP Update RequestCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationGHSA-vrw8-fxc6-2r93 chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashesCVE-2026-34986 github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) objectCVE-2025-27144 go-jose: Go JOSE's Parsing Vulnerable to Denial of ServiceCVE-2024-45339 github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glogCVE-2025-59530 github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE FrameCVE-2025-64702 github.com/quic-go/quic-go/http3: quic-go HTTP/3 QPACK Header Expansion DoSCVE-2026-40898 github.com/quic-go/quic-go: quic-go: Denial of Service via excessive memory allocation in HTTP/3 trailersCVE-2025-66406 github.com/smallstep/certificates: Step CA: Denial of Service via improper SSH certificate revocation authorizationCVE-2026-24051 opentelemetry-go: OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH HijackingCVE-2026-39883 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/SolarisCVE-2025-22869 golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/sshCVE-2025-47913 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESSCVE-2026-39828 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissionsCVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parametersCVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responsesCVE-2026-39831 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence checkCVE-2026-39832 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictionsCVE-2026-39835 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificateCVE-2026-42508 golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKeyCVE-2026-46595 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validationCVE-2026-46597 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputsCVE-2025-47914 golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messagesYour dependencies cross-checked against the OSV vulnerability database.
GO-2025-4180 Step CA Has Authorization Bypass in ACME and SCEP Provisioners in github.com/smallstep/certificatesGO-2026-4775 step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18) in github.com/smallstep/certificatesGO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshGO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshGO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsGO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshGO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGHSA-vrw8-fxc6-2r93 chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashesGO-2025-3485 DoS in go-jose Parsing in github.com/go-jose/go-joseGO-2026-4945 Go JOSE Panics in JWE decryption in github.com/go-jose/go-joseGO-2025-3372 Vulnerability when creating log files in github.com/golang/glogGO-2026-4518 Denial of service in github.com/jackc/pgproto3/v2GO-2025-4017 Panic occurs when queuing undecryptable packets after handshake completion in github.com/quic-go/quic-goGO-2025-4233 HTTP/3 QPACK Header Expansion DoS in github.com/quic-go/quic-goGO-2026-5676 HTTP/3 QPACK Trailer Expansion Memory Exhaustion in github.com/quic-go/quic-goGO-2025-4181 step-ca Has Improper Authorization Check for SSH Certificate Revocation in github.com/smallstep/certificatesGO-2026-4394 OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking in go.opentelemetry.io/otel/sdkGO-2026-5426 Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdkGO-2025-3487 Potential denial of service in golang.org/x/cryptoGO-2025-4134 Unbounded memory consumption in golang.org/x/crypto/sshGO-2025-4135 Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agentGO-2026-5013 Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/sshCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.