Use when generating Java code for web applications, APIs, or enterprise systems - prevents OWASP Top 10 vulnerabilities in Spring Boot, Jakarta EE, and core Java
Code generation guard that prevents security vulnerabilities while writing Java web application code. Covers OWASP Top 10 Web (2025), OWASP API Security Top 10 (2023), with CWE references throughout.
Stack: Java 11/17/21, Spring Boot, Spring Security, Jakarta EE, Hibernate, JPA
Java Version Focus:
Activate when generating code that:
PreparedStatement or JPA named parametersObjectInputStream.readObject() on untrusted data - use JSON with validationRuntime.exec() with user input - use ProcessBuilder with argument listjava.util.Random for security - use SecureRandomPath.resolve() + startsWith()userId before returning data| Module | Focus | Key Vulnerabilities |
|---|---|---|
| references/injection.md | SQL, Command, LDAP, XPath, JPQL | CWE-89, CWE-78, CWE-90, CWE-643 |
| references/deserialization.md | ObjectInputStream, XXE, JSON/YAML | CWE-502, CWE-611 |
| references/xss-output.md | XSS, template escaping, JSP/Thymeleaf | CWE-79 |
| references/auth-access.md | BOLA, BFLA, sessions, JWT | CWE-862, CWE-863, CWE-287 |
| references/crypto-secrets.md | Secrets, hashing, encryption | CWE-798, CWE-327, CWE-916 |
| references/input-validation.md | Bean Validation, forms, uploads | CWE-20, CWE-434, CWE-915 |
| references/file-operations.md | Path traversal, temp files, NIO | CWE-22, CWE-377 |
| references/spring-security.md | CSRF, CORS, method security, actuators | Spring-specific |
| references/jakarta-ee.md | Servlet security, EJB, JAX-RS | Jakarta EE-specific |
| references/dependencies.md | Maven/Gradle audit, supply chain | CWE-1104, CWE-1357 |
| references/java-runtime.md | Reflection, ReDoS, ScriptEngine | CWE-94, CWE-1333 |
User input involved?
āā Database query ā See references/injection.md (use PreparedStatement/JPA named params)
āā File path ā See references/file-operations.md (use Path.resolve() + startsWith check)
āā Command execution ā See references/injection.md (ProcessBuilder with list args)
āā Deserialization ā See references/deserialization.md (NEVER ObjectInputStream on untrusted)
āā Template rendering ā See references/xss-output.md (use th:text not th:utext)
āā API endpoint ā See references/auth-access.md + references/input-validation.md
Storing/generating secrets?
āā API keys ā See references/crypto-secrets.md (env vars or Vault)
āā Passwords ā See references/crypto-secrets.md (BCrypt/Argon2)
āā Tokens ā See references/crypto-secrets.md (SecureRandom)
Framework-specific?
āā Spring Boot ā See references/spring-security.md
āā Jakarta EE ā See references/jakarta-ee.md
āā Core Java ā See references/java-runtime.md