8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether aws-cdk-lib is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 3.3
GO-2026-6093
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
MEDIUM 6.6
CVE-2023-35165
AWS CDK EKS overly permissive trust policies
HIGH 7.3
CVE-2026-13760
aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
HIGH 7.3
CVE-2026-11417
aws-cdk-lib: OS Command Injection in NodejsFunction Bundling
LOW 2.2
GHSA-qc59-cxj2-c2w4
aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role
LOW 3.8
GHSA-5pq3-h73f-66hr
AWS CDK CodePipeline: trusted entities are too broad
MEDIUM 6.5
GHSA-qq4x-c6h6-rfxh
aws-cdk-lib has Insertion of Sensitive Information into Log File vulnerability when using Cognito UserPoolClient Construct
UNKNOWN
CVE-2025-23206
AWS Cloud Development Kit (AWS CDK) IAM OIDC custom resource allows connection to unauthorized OIDC provider
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes