Solution sectors / oss-libraries
Open Source Libraries
Open source libraries are reused across millions of projects, so one vulnerable package can cascade through the supply chain. This hub tracks CVEs across the major language package ecosystems and frameworks.
generic-library · 353web-framework · 121npm · 109pypi · 42go · 10crates-io · 9maven · 5packagist · 3nuget · 1rubygemshexpub
Cumulative CVEs
48,246
across 288 monthly snapshots
Latest month
929 · proj
-38.6% MoM · +114.1% YoY
Peak month
1,600
Mar 26
KEV this month
0
176 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Library88%
- Mixed7%
- On-prem5%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Open Source Libraries.
- CVE-2026-17434nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization6.3
- CVE-2026-17433nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization5.3
- CVE-2026-66011ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options3.3
- CVE-2026-66041FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter8.8
- CVE-2026-66040FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder8.8
- CVE-2026-66039FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File8.8
- CVE-2026-66038FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c6.5
- CVE-2026-66037FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()6.5
- CVE-2026-66036FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter8.8
- CVE-2026-66035libssh2 Heap Buffer Overflow via ETM Cipher Negotiation7.5
- CVE-2026-66034libssh2 Heap Out-of-Bounds Read via publickey subsystem7.5
- CVE-2026-66033libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation7.5
- CVE-2026-66032libssh2 Double-Free Heap Corruption via sftp_open()8.8
- CVE-2026-46452Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure5.3
- CVE-2026-45816Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request7.5
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| symfony | 56 | 8 | · |
| npm | 50 | · | · |
| imagemagick | 32 | · | · |
| crates.io | 31 | · | · |
| sensiolabs | 28 | 3 | · |
| capgo | 22 | · | · |
| curl | 18 | 8 | · |
| haxx | 18 | 8 | · |
| picklescan | 16 | · | · |
| eclipse foundation | 15 | 1 | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| generic-library | 353 | 63 | · | 90 | — | camel (34) · imagemagick (32) · symfony (28) |
| — | 156 | 16 | · | 26 | — | surrealdb (20) · curl (18) · picklescan (16) |
| web-framework | 121 | 21 | · | 31 | — | twig (34) · symfony (29) · corewcf (13) |
| npm | 109 | · | · | 12 | — | openclaw (68) · @asymmetric-effort/specifyjs (5) · node-tar (4) |
| pypi | 42 | · | · | 7 | — | pillow (13) · mistune (9) · pypdf (4) |
| go | 10 | · | · | 4 | — | fiber (3) · github.com/almeidapaulopt/tsdproxy (2) · crypto/tls (1) |
| crates-io | 9 | · | · | 2 | — | exploration (1) · jxl-modular (1) · jxl-oxide (1) |
| maven | 5 | · | · | 2 | — | com.arcadedb:arcadedb-engine (2) · com.arcadedb:arcadedb-server (2) · pgjdbc (1) |
| packagist | 3 | · | · | 1 | — | adawolfa/isdoc (1) · easycorp/easyadmin-bundle (1) · spatie/schema-org (1) |
| nuget | 1 | · | · | 1 | — | umbraco.ai (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification