Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2014-3499 docker: systemd socket activation results in privilege escalationCVE-2014-6407 docker: symbolic and hardlink issues leading to privilege escalationCVE-2014-9357 docker: Escalation of privileges during decompression of LZMA archivesCVE-2018-12608 moby: cert signing bypassCVE-2019-13509 docker: Docker Engine in debug mode may sometimes add secrets to the debug log leading to information disclosureCVE-2026-34040 Moby: Moby: Authorization bypass vulnerabilityCVE-2014-5277 docker: fallback to HTTP when HTTPS connections to the registry failCVE-2014-9356 docker: Path traversal during processing of absolute symlinksCVE-2014-9358 docker: Path traversal and spoofing opportunities presented through image identifiersCVE-2015-3627 docker: insecure opening of file-descriptor 1 leading to privilege escalationCVE-2015-3631 docker: volume mounts allow LSM profile escalationCVE-2020-27534 moby/buildkit: calls os.OpenFile with a potentially unsafe qemu-check temporary pathnameCVE-2021-41091 moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversalCVE-2022-24769 moby: Default inheritable capabilities for linux container should be emptyCVE-2022-36109 moby: supplementary groups mishandlingCVE-2024-24557 moby: classic builder cache poisoningCVE-2024-29018 moby: external DNS requests from 'internal' networks could lead to data exfiltrationCVE-2026-33997 moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installationGHSA-jq35-85cj-fj4p /sys/devices/virtual/powercap accessible by default to containersGHSA-xmmx-7jpf-fx42 Moby (Docker Engine) is vulnerable to Ambiguous OCI manifest parsingCVE-2023-37788 goproxy: Denial of service (DoS) via unspecified vectors.CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validationCVE-2024-45339 github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glogYour dependencies cross-checked against the OSV vulnerability database.
GO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/cryptoGO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshGO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshGO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsGO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshGO-2021-0238 Infinite loop when parsing inputs in golang.org/x/net/htmlGO-2022-0236 Panic due to large headers in net/http and golang.org/x/net/http/httpgutsGO-2022-0969 Denial of service in net/http and golang.org/x/net/http2GO-2022-1144 Excessive memory growth in net/http and golang.org/x/net/http2GO-2023-1571 Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/netGO-2023-1988 Improper rendering of text nodes in golang.org/x/net/htmlGO-2023-2102 HTTP/2 rapid reset can cause excessive work in net/httpGO-2024-2687 HTTP/2 CONTINUATION flood in net/httpGO-2025-3503 HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/netGO-2025-3595 Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/netGO-2026-5028 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/htmlGHSA-qppj-fm5r-hxr3 HTTP/2 Stream Cancellation AttackGO-2021-0064 Unauthorized credential disclosure via debug logs in k8s.io/kubernetes and k8s.io/client-goGO-2021-0053 Panic due to improper input validation in github.com/gogo/protobufGO-2022-0322 Uncontrolled resource consumption in github.com/prometheus/client_golangGO-2021-0227 Panic on crafted authentication request message in golang.org/x/crypto/sshGO-2021-0356 Denial of service via crafted Signer in golang.org/x/crypto/sshCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.