Fork of Google's OSV-Scanner with my fix for a stack-overflow DoS in the SPDX license parser (issue #2993, PR #3032): unbounded recursion on untrusted license expressions, now bounded with a depth limit.
golang security-audit google scanner bugfix stack-overflow denial-of-service spdx osv security-tools vulnerability-scanner security-research ameythakur amey osv-scanner open-source-contribution ameyarc cwe-674 amey-thakur license-parsing
-
Updated
Sep 6, 2026 - Go