Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
CVE-2017-7657 jetty: HTTP request smugglingCVE-2017-7658 jetty: Incorrect header handlingCVE-2017-7657 jetty: HTTP request smugglingCVE-2017-7658 jetty: Incorrect header handlingCVE-2014-3577 CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fixCVE-2015-5262 httpcomponents-core: missing HTTPS connection timeoutCVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIsCVE-2023-40167 jetty: Improper validation of HTTP/1 content-lengthCVE-2024-6763 org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authorityCVE-2017-7656 jetty: HTTP request smuggling using the range headerCVE-2021-28165 jetty: Resource exhaustion when receiving an invalid large TLS frameCVE-2018-12536 jetty: full server path revealed when using the default Error HandlingCVE-2019-10241 jetty: using specially formatted URL against DefaultServlet or ResourceHandler leads to XSS conditionsCVE-2019-10246 jetty: Directory Listing on Windows reveals Resource Base pathCVE-2019-10247 jetty: error path information disclosureCVE-2023-26048 jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()CVE-2021-28169 jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directoryCVE-2024-9823 org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilterCVE-2014-3577 CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fixCVE-2015-5262 httpcomponents-core: missing HTTPS connection timeoutCVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIsCVE-2022-45688 json stack overflow vulnerabilityCVE-2023-5072 JSON-java: parser confusion leads to OOMCVE-2014-3577 CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fixCVE-2015-5262 httpcomponents-core: missing HTTPS connection timeoutYour dependencies cross-checked against the OSV vulnerability database.
GHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-6x9x-8qw9-9pp6 Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)GHSA-vgg8-72f2-qm23 Critical severity vulnerability that affects org.eclipse.jetty:jetty-serverGHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderGHSA-gwrp-pvrq-jmwv Path Traversal and Improper Input Validation in Apache Commons IOGHSA-q446-82vq-w674 Improper Limitation of a Pathname to a Restricted Directory in JCraft JSchGHSA-cgp8-4m63-fhh5 Apache Commons Net vulnerable to information leakage via malicious serverGHSA-4vrv-ch96-6h42 Improper Privilege Management in MySQL Connectors JavaGHSA-g76j-4cxx-23h9 Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors JavaGHSA-jcq3-cprp-m333 Privilege escalation in mysql-connector-javGHSA-m6vm-37g8-gqvh MySQL Connectors takeover vulnerabilityGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-668q-qrv7-99fm Deserialization of Untrusted Data in logbackGHSA-pr98-23f8-jwxv QOS.CH logback-core Expression Language Injection vulnerabilityGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-7r82-7xv7-xcpj Cross-site scripting in Apache HttpClientGHSA-hmr7-m48g-48f6 Jetty accepts "+" prefixed value in Content-LengthGHSA-qh8g-58pp-2wxh Eclipse Jetty URI parsing of invalid authorityGHSA-26vr-8j45-3r4w Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resourcesGHSA-7vx9-xjhr-rw6h Cross-site Scripting in Eclipse JettyGHSA-84q7-p226-4x5w Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)GHSA-9rgv-h7x4-qw8g Eclipse Jetty Server generates error message containing sensitive informationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.