Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 10 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 10 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
10 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
72 of 45289 files scanned (<1%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Read 72 of 317 selected files — this repository's archive was too large to finish in one scan.
Two scanners read 72 of 45289 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 10 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
0.0.6 — GHSA-2jv5-9r88-3w3p, GHSA-59g5-xgcq-4qw3, GHSA-5rvq-cxj2-64vf
python-multipart vulnerable to Content-Type Header ReDoS — HIGH
Denial of service (DoS) via deformation `multipart/form-data` boundary — HIGH
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service — HIGH
0.14.1 — GHSA-4c29-8rgm-jvjj, GHSA-4vrq-3vrq-g6gg
BuildKit's Malicious frontend can cause file escape outside of storage root — HIGH
BuildKit Git URL subdir component can cause access to restricted files — HIGH
3.4.0 — GHSA-55q2-fjhq-7xh7, GHSA-76mc-f452-cxcm, GHSA-c2j3-45gr-mqc4
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS — MODERATE
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` — MODERATE
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. — LOW
1.7.18 — GHSA-265r-hfxg-fhmg, GHSA-jpcc-p29g-p8mq, GHSA-m6hq-p25p-ffr2
containerd has an integer overflow in User ID handling — MODERATE
containerd image-triggered runtime DoS via unbounded group parsing — MODERATE
containerd CRI server: Host memory exhaustion through Attach goroutine leak — MODERATE
11.15.0 — GHSA-2v8p-3f2j-5mp7, GHSA-3rrr-jr9j-h3q3, GHSA-6x64-9x62-f2gx
Mermaid XY Charts are vulnerable to an infinite loop DoS — MODERATE
Mermaid Architecture diagrams are vulnerable to prototype pollution — MODERATE
Mermaid allows CSS injection applying to sibling elements of the diagram — MODERATE
1.24.1 — GHSA-6hxr-mr5r-9836, GHSA-8hcv-x26h-mcgp, GHSA-ff84-5f28-78qj
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS) — MODERATE
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length — MODERATE
re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS) — MODERATE
2.31.0 — GHSA-9hjg-9r4m-mvj7, GHSA-9wx4-h78v-vm56, GHSA-gc5v-m9x4-r6x2
Requests vulnerable to .netrc credentials leak via malicious URLs — MODERATE
Requests `Session` object does not verify requests after making first request with verify=False — MODERATE
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function — MODERATE
6.25.0 — GHSA-35p6-xmwp-9g52, GHSA-8xcm-r25x-g524, GHSA-g8m3-5g58-fq7m
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse — LOW
undici vulnerable to downstream response desynchronization via retry interceptor — MODERATE
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching — LOW
1.11.0 — GHSA-434x-w66g-qw3r, RUSTSEC-2026-0007
bytes has integer overflow in BytesMut::reserve — MODERATE
Integer overflow in `BytesMut::reserve` — UNKNOWN
2.1.3 — GHSA-36gq-35j3-p9r9, GO-2025-3412
Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop — MODERATE
Excessive resource consumption when unmarshalling Compose file with recursive loop in github.com/compose-spec/compose-go/v2 — UNKNOWN
0.15.1 — GHSA-m4gq-fm9h-8q75, GO-2025-3527
buildx allows a possible credential leakage to telemetry endpoint — MODERATE
buildx allows a possible credential leakage to telemetry endpoint in github.com/docker/buildx — UNKNOWN
27.1.1 — GHSA-4vq8-7jfc-9cvp, GHSA-pxq6-2prw-chj9
Moby firewalld reload removes bridge network isolation — LOW
Moby has an Off-by-one error in its plugin privilege validation — MODERATE
2.3.0 — GHSA-2464-8j7c-4cjm, GO-2025-3900
go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data — MODERATE
Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure — UNKNOWN
0.5.0 — GHSA-pmwq-pjrm-6p5r, GO-2026-5547
in-toto-golang and in-toto-python have inconsistent negation behavior — MODERATE
in-toto-golang and in-toto-python have inconsistent negation behavior in github.com/in-toto/in-toto-golang — UNKNOWN
7.4.3 — GHSA-6w46-j5rx-g56g, PYSEC-2026-1845
pytest has vulnerable tmpdir handling — devDependency
pytest has vulnerable tmpdir handling — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 72 of 45289 files (highest-priority subset) · PostHog/posthog
Dependency manifests: 25 package roots found, 13 scanned; 2 Python manifests read; 2 Go manifests read; 4 Rust manifests read — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)