Solution sectors / oss-libraries
Open Source Libraries
Open source libraries are reused across millions of projects, so one vulnerable package can cascade through the supply chain. This hub tracks CVEs across the major language package ecosystems and frameworks.
generic-library · 153web-framework · 39npm · 12pypi · 10go · 2rubygems · 1mavencrates-ionugetpackagisthexpub
Cumulative CVEs
49,079
across 289 monthly snapshots
Latest month
788 · proj
-41.1% MoM · +58.9% YoY
Peak month
1,600
Mar 26
KEV this month
0
70 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Library91%
- Mixed6%
- On-prem3%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Open Source Libraries.
- CVE-2026-49467TOTP enrollment hijack: password gate skipped due to unawaited promise8.8
- CVE-2026-73291Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag7.1
- CVE-2026-73290RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback5.3
- CVE-2026-73289RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions8.1
- CVE-2026-73287RustFS: FTPS MKD bypasses IAM CreateBucket authorization5.4
- CVE-2026-73286RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions8.1
- CVE-2026-73285RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged7.5
- CVE-2026-73284RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts8.8
- CVE-2026-73265RustFS: Version-specific object reads authorize the non-version action6.5
- CVE-2026-68868Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables6.5
- CVE-2026-19588Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.6.5
- CVE-2026-9318tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title5.4
- CVE-2026-19587Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.6.5
- CVE-2026-5917libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend9.6
- CVE-2026-29036cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding7.5
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| bouncycastle | 34 | · | · |
| freerdp | 23 | 3 | · |
| packagist | 18 | · | · |
| better-auth | 17 | 1 | · |
| electron | 16 | · | · |
| eclipse foundation | 14 | 2 | · |
| axios | 10 | · | · |
| npm | 9 | · | · |
| pypi | 9 | · | · |
| go | 8 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| generic-library | 153 | 23 | · | 39 | — | langflow oss (24) · electron (16) · apache cxf (12) |
| — | 88 | 5 | · | 12 | — | freerdp (23) · craftcms/cms (10) · gitpython (9) |
| web-framework | 39 | 2 | · | 10 | — | better-auth (11) · nuxt (6) · hono (4) |
| npm | 12 | 1 | · | 3 | — | axios (10) · ngx-extended-pdf-viewer (1) · sequelize (1) |
| pypi | 10 | · | · | 4 | — | cryptography (3) · pdm (3) · pymdown-extensions (2) |
| go | 2 | · | · | 1 | — | go-git (2) |
| rubygems | 1 | · | · | 1 | — | json (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification