gitsafehub
github.com/tsegismont/reactiverse-junit5-extensions ↗

tsegismont/reactiverse-junit5-extensions

scanned 2026-08-08 · git 9d7206a
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies47Known OSS vulnerabilities4Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 47 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2025-52999). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (GHSA-r7wm-3cxj-wff9). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-49128 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocation
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2025-49128). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33870 io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-33870). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42584 netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-42584). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42587 netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-42587). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-55831 io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-55831). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-55833 netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-55833). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-56745 netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-56745). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-21290 netty: Information disclosure via the local system temporary directory
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2021-21290). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-43797 netty: control chars in header names may lead to HTTP request smuggling
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2021-43797). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-24823 netty: world readable temporary file containing sensitive data
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2022-24823). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-29025 netty-codec-http: Allocation of Resources Without Limits or Throttling
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2024-29025). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-67735 netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2025-67735). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41417 netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-41417). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42580 netty: Netty: Request smuggling via chunk size parser integer overflow
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-42580). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42581 netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-42581). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42585 netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-42585). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-50020 netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-50020). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-56746 io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-56746). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59898 io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-59898). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59899 io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-59899). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59921 io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-59921). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-55163 netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2025-55163). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33871 netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
    reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-33871). Fix: Update that package to its patched version.
… 22 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 4 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing GHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion
    /workdirs/scan-65254a50-8241-473e-ac03-f99bdcb47453/pom.xml
    A package you depend on has a known security hole (CVE-2026-24400). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion
    /workdirs/scan-65254a50-8241-473e-ac03-f99bdcb47453/reactiverse-junit5-web-client-rx-java/pom.xml
    A package you depend on has a known security hole (CVE-2026-24400). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion
    /workdirs/scan-65254a50-8241-473e-ac03-f99bdcb47453/reactiverse-junit5-web-client-rx-java2/pom.xml
    A package you depend on has a known security hole (CVE-2026-24400). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion
    /workdirs/scan-65254a50-8241-473e-ac03-f99bdcb47453/reactiverse-junit5-web-client/pom.xml
    A package you depend on has a known security hole (CVE-2026-24400). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.