This release appears generally healthy to depend on: it has a substantial release history, frequent recent releases, a stable non-prerelease version, no registry deprecation, no runtime dependencies, and Maven PGP-signed provenance. The main concerns are transparency and verification gaps: no source repository is declared, and the artifact exposes no README, tests, or changelog; these are meaningful limitations for assessing ongoing maintenance, though the missing documentation is less concerning for a compiled library artifact. Overall, the package is usable with moderate confidence, but consumers should perform additional project and release verification before adopting it for critical systems.
78%
Total Score
100
90
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-371771 New springdoc-openapi-starter-common is vulnerable to Uncontrolled Resource Consumption in versions 2.0.0 - 2.9.0 and 3.0.0 - 3.1.0. | 2.0.0 - 2.9.03.0.0 - 3.1.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework.boot:spring-boot-starter Version * | — | — |
org.springframework.boot:spring-boot-autoconfigure Version * | — | — |
org.springframework.boot:spring-boot-validation Version * | — | — |
io.swagger.core.v3:swagger-core-jakarta Version * | — | — |
org.springframework.boot:spring-boot-jackson Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.