Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2025-49128 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocationCVE-2026-33870 io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension valuesCVE-2026-42584 netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusionCVE-2026-42587 netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompressionCVE-2026-55831 io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processingCVE-2026-55833 netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplificationCVE-2026-56745 netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codecCVE-2021-21290 netty: Information disclosure via the local system temporary directoryCVE-2021-43797 netty: control chars in header names may lead to HTTP request smugglingCVE-2022-24823 netty: world readable temporary file containing sensitive dataCVE-2024-29025 netty-codec-http: Allocation of Resources Without Limits or ThrottlingCVE-2025-67735 netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF InjectionCVE-2026-41417 netty: Netty: HTTP request smuggling via URI manipulation and CRLF injectionCVE-2026-42580 netty: Netty: Request smuggling via chunk size parser integer overflowCVE-2026-42581 netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headersCVE-2026-42585 netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsingCVE-2026-50020 netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoderCVE-2026-56746 io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin headerCVE-2026-59898 io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)CVE-2026-59899 io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)CVE-2026-59921 io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoderCVE-2025-55163 netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS VulnerabilityCVE-2026-33871 netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame floodYour dependencies cross-checked against the OSV vulnerability database.
GHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertionGHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertionGHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertionGHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertionCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.