logo

CISA's Flags Memory-Unsafe Code in Major Open Source Projects

ID: 13f6737e-a9a1-5a52-8999-9199fa597ba0

STIX ID: report--13f6737e-a9a1-5a52-8999-9199fa597ba0

Feed Name: Dark Reading

Date Published: 2024-06-28

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A CISA-led analysis finds extensive use of memory-unsafe languages in major open-source projects—52% of 172 projects contained memory-unsafe code and 55% of combined lines were memory-unsafe—creating broad exposure to buffer-overflow and use-after-free vulnerabilities; the report highlights dependency risks, disabled safety features, and the high cost and complexity of migrating large codebases to memory-safe languages (Rust, Go, Java, etc.), and recommends continued adoption of memory-safe languages, secure coding practices, and rigorous security testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.