Maven · repo1.maven.org
com.zaxxer:HikariCP
Java Jndi Lookup: JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family).
Why PkgRadar flagged 7.1.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Java Jndi Lookup | JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family). · com/zaxxer/hikari/HikariJNDIFactory.java |
| medium | Java Jndi Lookup | JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family). · com/zaxxer/hikari/HikariConfig.java |
| medium | Java Jndi Lookup | JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family). · com/zaxxer/hikari/pool/PoolBase.java |
| medium | Remote Payload | matched "cUrl " · com/zaxxer/hikari/util/DriverDataSource.java |
| medium | Remote Payload | matched "cUrl " · com/zaxxer/hikari/HikariConfig.java |
| medium | Remote Payload | matched "cUrl " · com/zaxxer/hikari/pool/PoolBase.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
7.1.0 | High risk | 43 | 2026-06-14 |
Block this in CI
pkgradar gate --ecosystem maven com.zaxxer:[email protected]