CVE Tools

Open Source Libraries

50,831 CVEs tracked since 1999. In the last 12 months, 11,859, +137% on the 12 before.

Open Source Libraries by subsector, Sep 2026 so far

Sep 2026 so far: 749 CVEs across 8 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Other libraries35748% · 82 vendors
  • Not yet sub-classified187The tagger has not placed these yet
  • Web frameworks9413% · 29 vendors
  • npm8511% · 17 vendors

Also: PyPI 13, Go modules 7, NuGet 4, crates.io 2.

Month by month

Every monthly snapshot of Open Source Libraries. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Open Source Libraries CVEs per month
MonthCVEs
2021-09354
2021-10241
2021-11340
2021-12364
2022-01545
2022-02457
2022-03482
2022-04352
2022-05412
2022-06540
2022-07374
2022-08402
2022-09552
2022-10348
2022-11438
2022-12510
2023-01403
2023-02417
2023-030
2023-04448
2023-05381
2023-06413
2023-07361
2023-08448
2023-09399
2023-10405
2023-11377
2023-12438
2024-01433
2024-02494
2024-03447
2024-04431
2024-05719
2024-06437
2024-07394
2024-08313
2024-09361
2024-10432
2024-11389
2024-12320
2025-01351
2025-02347
2025-03623
2025-04466
2025-05369
2025-06420
2025-07434
2025-08496
2025-09487
2025-10543
2025-11369
2025-12550
2026-01842
2026-021015
2026-031600
2026-041120
2026-051175
2026-061513
2026-071337
2026-081308
2026-09749

Vendors

Who shipped the most Open Source Libraries CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Ash-project37#27
  2. Patriksimek34#31
  3. Freerdp22#48
  4. Eclipse Foundation20#51
  5. npm20#53
  6. HTTP4S19#56
  7. Erlang16#71
  8. Xmldom15#81

Weaknesses

The weakness classes behind Open Source Libraries CVEs in Sep 2026 so far.

  1. CWE-125 Out-of-bounds Read45
  2. CWE-863 Incorrect Authorization43
  3. CWE-22 Path Traversal41
  4. CWE-79 XSS34
  5. CWE-122 Heap Buffer Overflow26
  6. CWE-200 Information Exposure25

Latest CVEs

The 15 most recently published vulnerabilities in Open Source Libraries.

  1. CVE-2026-15442Heap use-after-free on read during bidirectional (D)TLS shutdown—
  2. CVE-2026-89102OCSP stapling v2 multi accepts non-CA chain certificates as issuers—
  3. CVE-2026-89133NameConstraints not enforced across unconstrained intermediate CA—
  4. CVE-2026-89134Subject CN name-constraint check bypassed when non-DNS SAN present—
  5. CVE-2026-89135Failed X509_verify_cert leaves unverified CA in shared CertManager—
  6. CVE-2026-89136Client accepts unsolicited RawPublicKey server certificate type—
  7. CVE-2026-93302Trusted peer certificate match ignores public key, allowing forged CA clones—
  8. CVE-2026-93304(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange—
  9. CVE-2026-94417CRL check skipped when OCSP enabled and certificate has no OCSP URL—
  10. CVE-2026-94418Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY—
  11. CVE-2026-94419Client session cache reference poisoning allows resumption with wrong server—
  12. CVE-2026-100837Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching3.7
  13. CVE-2026-100836Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer4.3
  14. CVE-2026-100839Contrast before 1.18.0 AML Injection Remote Code Execution8.4
  15. CVE-2026-100838Contrast before 1.19.1 CopyFile Policy Symlink Subversion8.1

The record

Busiest month
Mar 2026, 1,600 CVEs
Sep 2026 so far
749 CVEs from 172 vendors
Deployment
Library, 84%
Monthly snapshots
290 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store