Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2018-11307 jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatisCVE-2018-14718 jackson-databind: arbitrary code execution in slf4j-ext classCVE-2018-14719 jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classesCVE-2018-14720 jackson-databind: exfiltration/XXE in some JDK classesCVE-2018-14721 jackson-databind: server-side request forgery (SSRF) in axis2-jaxws classCVE-2018-19360 jackson-databind: improper polymorphic deserialization in axis2-transport-jms classCVE-2018-19361 jackson-databind: improper polymorphic deserialization in openjpa classCVE-2018-19362 jackson-databind: improper polymorphic deserialization in jboss-common-core classCVE-2019-14379 jackson-databind: default typing mishandling leading to remote code executionCVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfigCVE-2019-16335 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSourceCVE-2019-16942 jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.*CVE-2019-16943 jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSourceCVE-2019-17267 jackson-databind: Serialization gadgets in classes of the ehcache packageCVE-2019-17531 jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.*CVE-2019-20330 jackson-databind: lacks certain net.sf.ehcache blockingCVE-2020-8840 jackson-databind: Lacks certain xbean-reflect/JNDI blockingCVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-configCVE-2020-9547 jackson-databind: Serialization gadgets in ibatis-sqlmapCVE-2020-9548 jackson-databind: Serialization gadgets in anteros-coreCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2022-22978 springframework: Authorization Bypass in RegexRequestMatcherCVE-2022-22978 springframework: Authorization Bypass in RegexRequestMatcherCVE-2024-38821 Spring-WebFlux: Authorization Bypass of Static Resources in WebFlux ApplicationsCVE-2026-22732 Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headersYour dependencies cross-checked against the OSV vulnerability database.
GHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-4gq5-ch57-c2mg Arbitrary Code Execution in jackson-databindGHSA-4w82-r329-3q67 Deserialization of Untrusted Data in jackson-databindGHSA-5p34-5m6p-p58g jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-645p-88qh-w398 Arbitrary Code Execution in jackson-databindGHSA-6fpp-rgj9-8rwc Deserialization of untrusted data in FasterXML jackson-databindGHSA-85cw-hj65-qqv9 Polymorphic Typing issue in FasterXML jackson-databindGHSA-9mxf-g3x6-wv74 Server-Side Request Forgery (SSRF) in jackson-databindGHSA-c8hm-7hpq-7jhg com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted DataGHSA-f3j5-rmmp-3fc5 Improper Input Validation in jackson-databindGHSA-f9hv-mg5h-xcw9 Deserialization of Untrusted Data in jackson-databind due to polymorphic deserializationGHSA-fmmc-742q-jg75 jackson-databind polymorphic typing issueGHSA-gjmw-vf9h-g25v jackson-databind polymorphic typing issueGHSA-gww7-p5w4-wrfv Deserialization of Untrusted Data in jackson-databindGHSA-h822-r4r5-v8jg Polymorphic Typing issue in FasterXML jackson-databindGHSA-mx7p-6679-8g3q Polymorphic Typing in FasterXML jackson-databindGHSA-mx9v-gmh4-mgqw Deserialization of Untrusted Data in jackson-databindGHSA-p43x-xfjf-5jhr jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-q93h-jc49-78gg jackson-databind mishandles the interaction between serialization gadgets and typingGHSA-qr7j-h6gg-jmgc Deserialization of Untrusted Data in jackson-databindGHSA-x2w5-5m2g-7h5m XML External Entity Reference (XXE) in jackson-databindGHSA-5j33-cvvr-w245 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityGHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly appliedGHSA-83qj-6fr2-vhqg Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTGHSA-c9hw-wf7x-jp9j Improper Privilege Management in TomcatCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.