Open Source Libraries
50,831 CVEs tracked since 1999. In the last 12 months, 11,859, +137% on the 12 before.
Open Source Libraries by subsector, Sep 2026 so far
- Other libraries35748% · 82 vendors
- Not yet sub-classified187The tagger has not placed these yet
- Web frameworks9413% · 29 vendors
- npm8511% · 17 vendors
Also: PyPI 13, Go modules 7, NuGet 4, crates.io 2.
Month by month
Every monthly snapshot of Open Source Libraries. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 354 |
| 2021-10 | 241 |
| 2021-11 | 340 |
| 2021-12 | 364 |
| 2022-01 | 545 |
| 2022-02 | 457 |
| 2022-03 | 482 |
| 2022-04 | 352 |
| 2022-05 | 412 |
| 2022-06 | 540 |
| 2022-07 | 374 |
| 2022-08 | 402 |
| 2022-09 | 552 |
| 2022-10 | 348 |
| 2022-11 | 438 |
| 2022-12 | 510 |
| 2023-01 | 403 |
| 2023-02 | 417 |
| 2023-03 | 0 |
| 2023-04 | 448 |
| 2023-05 | 381 |
| 2023-06 | 413 |
| 2023-07 | 361 |
| 2023-08 | 448 |
| 2023-09 | 399 |
| 2023-10 | 405 |
| 2023-11 | 377 |
| 2023-12 | 438 |
| 2024-01 | 433 |
| 2024-02 | 494 |
| 2024-03 | 447 |
| 2024-04 | 431 |
| 2024-05 | 719 |
| 2024-06 | 437 |
| 2024-07 | 394 |
| 2024-08 | 313 |
| 2024-09 | 361 |
| 2024-10 | 432 |
| 2024-11 | 389 |
| 2024-12 | 320 |
| 2025-01 | 351 |
| 2025-02 | 347 |
| 2025-03 | 623 |
| 2025-04 | 466 |
| 2025-05 | 369 |
| 2025-06 | 420 |
| 2025-07 | 434 |
| 2025-08 | 496 |
| 2025-09 | 487 |
| 2025-10 | 543 |
| 2025-11 | 369 |
| 2025-12 | 550 |
| 2026-01 | 842 |
| 2026-02 | 1015 |
| 2026-03 | 1600 |
| 2026-04 | 1120 |
| 2026-05 | 1175 |
| 2026-06 | 1513 |
| 2026-07 | 1337 |
| 2026-08 | 1308 |
| 2026-09 | 749 |
Vendors
Who shipped the most Open Source Libraries CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Open Source Libraries CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Open Source Libraries.
- CVE-2026-15442Heap use-after-free on read during bidirectional (D)TLS shutdown—
- CVE-2026-89102OCSP stapling v2 multi accepts non-CA chain certificates as issuers—
- CVE-2026-89133NameConstraints not enforced across unconstrained intermediate CA—
- CVE-2026-89134Subject CN name-constraint check bypassed when non-DNS SAN present—
- CVE-2026-89135Failed X509_verify_cert leaves unverified CA in shared CertManager—
- CVE-2026-89136Client accepts unsolicited RawPublicKey server certificate type—
- CVE-2026-93302Trusted peer certificate match ignores public key, allowing forged CA clones—
- CVE-2026-93304(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange—
- CVE-2026-94417CRL check skipped when OCSP enabled and certificate has no OCSP URL—
- CVE-2026-94418Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY—
- CVE-2026-94419Client session cache reference poisoning allows resumption with wrong server—
- CVE-2026-100837Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching3.7
- CVE-2026-100836Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer4.3
- CVE-2026-100839Contrast before 1.18.0 AML Injection Remote Code Execution8.4
- CVE-2026-100838Contrast before 1.19.1 CopyFile Policy Symlink Subversion8.1
The record
- Busiest month
- Mar 2026, 1,600 CVEs
- Sep 2026 so far
- 749 CVEs from 172 vendors
- Deployment
- Library, 84%
- Monthly snapshots
- 290 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment