PkgRadar

Maven · repo1.maven.org

io.swagger.parser.v3:swagger-parser-v3

Java Base64 Combo: Base64.decode combined with network / process / defineClass — classic obfuscated payload.

Why PkgRadar flagged 2.1.44

SeveritySignalEvidence
highJava Base64 ComboBase64.decode combined with network / process / defineClass — classic obfuscated payload. · io/swagger/v3/parser/util/OpenAPIDeserializer.java
highJava Static Init Side EffectStatic-initializer block contains process/network/reflection — runs on first class load. · io/swagger/v3/parser/util/OpenAPIDeserializer.java

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.44High risk422026-06-12

Block this in CI

PkgRadar gates io.swagger.parser.v3:swagger-parser-v3 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven io.swagger.parser.v3:[email protected]