Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2021-22569 protobuf-java: potential DoS in the parsing procedure for binary dataCVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol BuffersCVE-2022-3171 protobuf-java: timeout in parser leads to DoSCVE-2014-3643 jersey: XXE via parameter entitiesCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2023-26464 log4j1-socketappender: DoS via hashmap loggingCVE-2021-35515 apache-commons-compress: infinite loop when reading a specially crafted 7Z archiveCVE-2021-35516 apache-commons-compress: excessive memory allocation when reading a specially crafted 7Z archiveCVE-2021-35517 apache-commons-compress: excessive memory allocation when reading a specially crafted TAR archiveCVE-2021-36090 apache-commons-compress: excessive memory allocation when reading a specially crafted ZIP archiveCVE-2024-25710 commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP fileCVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissionsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-8wm5-8h9c-47pc Apache Hadoop argument injection vulnerabilityGHSA-gx2c-fvhc-ph4j Path traversal in HadoopGHSA-rmpj-7c96-mrg8 Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2GHSA-895m-ww55-59vw Exposure of Sensitive Information to an Unauthorized Actor in Apache HadoopGHSA-3vrc-rrpw-r5pw java-xmlbuilder vulnerable to XML External Entity ReferenceGHSA-fjq5-5j5f-mvxh Deserialization of Untrusted Data in Apache commons collectionsGHSA-cqqj-4p63-rrmm HTTP Request Smuggling in NettyGHSA-r7pg-v2c8-mfg3 Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)GHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperGHSA-c27h-mcmw-48hv Deserialization of Untrusted Data in org.codehaus.jackson:jackson-mapper-aslGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-mvr2-9pj6-7w5j Denial of Service in Google GuavaGHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderGHSA-gwrp-pvrq-jmwv Path Traversal and Improper Input Validation in Apache Commons IOGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-fp5r-v3w9-4333 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted dataGHSA-vp98-w2p3-mv35 Apache Log4j 1.x (EOL) allows Denial of Service (DoS)GHSA-w9p3-5cr8-m3jj Deserialization of Untrusted Data in Log4j 1.xGHSA-7q56-mp4c-gggg Improper Access Control in Apache HadoopGHSA-8r28-r8cp-g6cp Exposure of Sensitive Information to an Unauthorized Actor in Apache HadoopGHSA-f8vc-wfc8-hxqh Improper Privilege Management in Apache HadoopCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.