Open Source Vulnerabilities Hit Four-Year Low in 2025: Backlog Cleared, But New Threats Surge
GitHub reviewed just 4,101 open source advisories in 2025—the fewest since 2021. But don't pop the champagne; new vulnerabilities jumped 19%, signaling no safety net yet.
theAIcatchupApr 07, 20263 min read18 views
⚡ Key Takeaways
Reviewed advisories hit 4-year low at 4,101, but new vulns up 19% YoY.𝕏
CWE shifts: Resource exhaustion and SSRF surged; tagging improved 85%.𝕏
npm malware spiked 69%; prioritize EPSS + CVSS for real threats.𝕏
The 60-Second TL;DR
Reviewed advisories hit 4-year low at 4,101, but new vulns up 19% YoY.
CWE shifts: Resource exhaustion and SSRF surged; tagging improved 85%.
npm malware spiked 69%; prioritize EPSS + CVSS for real threats.