logo

CISA: Most critical open source projects not using memory safe code

ID: 6e577284-d388-5790-bd87-99f007a12b4c

STIX ID: report--6e577284-d388-5790-bd87-99f007a12b4c

Feed Name: Bleeping Computer

Date Published: 2024-06-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** A joint CISA/FBI/ASD/CCCS analysis of 172 critical open-source projects found that over half contain memory-unsafe code (52% of projects, 55% of total lines), with major projects like Linux, Tor, Chromium, MySQL, glibc, and Redis showing high ratios; the report recommends adopting memory-safe languages, auditing dependencies, and applying continuous testing (static/dynamic analysis and fuzzing) to reduce memory-safety vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.