Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requestsCVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connectionsCVE-2026-6790 jetty: Jetty: Improper Host header validation can lead to request routing issuesCVE-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requestsCVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connectionsCVE-2026-6790 jetty: Jetty: Improper Host header validation can lead to request routing issuesCVE-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requestsCVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connectionsCVE-2026-6790 jetty: Jetty: Improper Host header validation can lead to request routing issuesCVE-2026-2332 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsingCVE-2026-10050 In Eclipse Jetty, the Digest authentication server-side component uses ...CVE-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requestsCVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connectionsCVE-2026-6790 jetty: Jetty: Improper Host header validation can lead to request routing issuesCVE-2026-8384 jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applicationsCVE-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requestsCVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connectionsCVE-2026-6790 jetty: Jetty: Improper Host header validation can lead to request routing issuesCVE-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requestsCVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connectionsCVE-2026-6790 jetty: Jetty: Improper Host header validation can lead to request routing issuesCVE-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requestsCVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connectionsCVE-2026-6790 jetty: Jetty: Improper Host header validation can lead to request routing issuesCVE-2026-2332 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsingYour dependencies cross-checked against the OSV vulnerability database.
GHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingGHSA-2fvj-hgj9-j2gr Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitutionGHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatchGHSA-f4v5-65jj-pcr2 Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connectionsGHSA-xxh7-fcf3-rj7f The Eclipse Jetty Server Artifact has a Gzip request memory leak GHSA-w7x5-g22v-xqhr Eclipse Jetty: Path parameter traversalGHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingGHSA-2fvj-hgj9-j2gr Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitutionGHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatchGHSA-f4v5-65jj-pcr2 Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connectionsGHSA-xxh7-fcf3-rj7f The Eclipse Jetty Server Artifact has a Gzip request memory leak GHSA-w7x5-g22v-xqhr Eclipse Jetty: Path parameter traversalGHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingGHSA-2fvj-hgj9-j2gr Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitutionGHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatchGHSA-f4v5-65jj-pcr2 Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connectionsGHSA-xxh7-fcf3-rj7f The Eclipse Jetty Server Artifact has a Gzip request memory leak GHSA-w7x5-g22v-xqhr Eclipse Jetty: Path parameter traversalGHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingGHSA-2fvj-hgj9-j2gr Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitutionGHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatchGHSA-f4v5-65jj-pcr2 Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connectionsGHSA-xxh7-fcf3-rj7f The Eclipse Jetty Server Artifact has a Gzip request memory leak GHSA-w7x5-g22v-xqhr Eclipse Jetty: Path parameter traversalGHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.