Solution sectors / oss-libraries
Open Source Libraries
Open source libraries are reused across millions of projects, so one vulnerable package can cascade through the supply chain. This hub tracks CVEs across the major language package ecosystems and frameworks.
generic-library · 198npm · 44web-framework · 27nuget · 4pypi · 3go · 2crates-io · 2mavenrubygemspackagisthexpub
Cumulative CVEs
50,471
across 290 monthly snapshots
Latest month
778 · proj
-40.5% MoM · +59.8% YoY
Peak month
1,600
Mar 26
KEV this month
1
101 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Library86%
- Mixed9%
- On-prem5%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Open Source Libraries.
- CVE-2026-90835michaelliao itranswarp Page Content Rendering Markdown.java Markdown.toHtml cross site scripting3.5
- CVE-2026-90831GNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruption5.3
- CVE-2026-90830GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereference5.3
- CVE-2026-90829GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereference5.3
- CVE-2026-90828GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereference5.3
- CVE-2026-12944Incomplete Security Scanner Blocklist Enables Network-Based Code Execution9.6
- CVE-2026-12763Langflow is vulnerable to authentication bypass and insufficient session expiration4.2
- CVE-2026-12765Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components6.5
- CVE-2026-12766Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components5.4
- CVE-2026-12767Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches6.5
- CVE-2026-55244ASTEVAL: Sandbox Escape via BaseException Subclasses5.0
- CVE-2026-17628Langflow is affected by improper authentication due to missing password verification in the password reset endpoint5.4
- CVE-2026-54181backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted5.4
- CVE-2026-54177backpack/crud: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserver6.6
- CVE-2026-54176backpack/crud: MyAccountController allows changing the login email without a current-password check6.5
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| ash-project | 36 | · | · |
| npm | 19 | · | · |
| erlang | 16 | · | · |
| eclipse foundation | 15 | · | · |
| xmldom | 15 | · | · |
| undici | 11 | · | · |
| curl | 9 | 2 | · |
| ocaml | 9 | 1 | · |
| thephpleague | 9 | · | · |
| haxx | 8 | 2 | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| generic-library | 198 | 13 | 1 | 50 | — | langflow oss (35) · otp (16) · commonmark (9) |
| — | 109 | 7 | · | 23 | — | ash (17) · arm 5th gen gpu architecture kernel driver (8) · curl (8) |
| npm | 44 | · | · | 10 | — | xmldom (15) · undici (11) · @openclaw/feishu (2) |
| web-framework | 27 | 2 | · | 14 | — | angular (5) · fastify (4) · hono (3) |
| nuget | 4 | · | · | 1 | — | microsoft.diasymreader.native (3) · microsoft.aspnetcore.server.iisintegration (1) |
| pypi | 3 | · | · | 1 | — | pypdf (3) |
| go | 2 | · | · | 1 | — | golang.org/x/crypto/ssh (2) |
| crates-io | 2 | · | · | 1 | — | mistralrs-server-core (2) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification