logo

A year of open source vulnerability trends: CVEs, advisories, and malware

ID: d42a2e28-5e6e-52a4-8540-2125d78f9634

STIX ID: report--d42a2e28-5e6e-52a4-8540-2125d78f9634

Feed Name: GitHub Security Lab

Threat Score
10/100

Date Published: 2026-03-26

Date Updated: 2026-04-27

Author: Jonathan Evans

...
...

GitHub’s 2025 Advisory Database review summarizes ecosystem and vulnerability trends: 4,101 reviewed advisories, a 69% year-over-year rise in published malware advisories (7,197), 2,903 CVEs published (35% increase), shifts in top CWEs (XSS/CWE-79 remaining dominant, rises in resource exhaustion, unsafe deserialization, SSRF, and reclassifications), improved CWE tagging, ecosystem coverage notes (Go overrepresented), and guidance for prioritization (CVSS/EPSS), use of CNA services, and enabling Dependabot and malware alerts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.