Open source vulnerability advisories tripled in a year, and a tenth carry no CVE at all
Reviewed open source package advisories hit 10,734 in the twelve months to 31 August 2026, up from 3,191 a year earlier, according to Axis Intelligence Research. 1,273 of them, 11.9%, carry no CVE identifier.

Axis Intelligence Research published the numbers on 4 September. The team worked from a full local clone of the GitHub Advisory Database and counted every non-withdrawn, human-reviewed advisory published between 1 September 2025 and 31 August 2026. The same window a year earlier produced 3,191. That is 3.36 times the volume, or 236.4% growth.
The break comes in March 2026. Monthly volume roughly doubled from February and has not returned to the old baseline since.
The obvious explanation, that researchers are backfilling old bugs, does not hold. Of the 9,393 advisories published January through August 2026, 8,005 carry a 2026 CVE identifier and 1,150 carry no CVE at all. Fewer than 4% reach back to a pre-2026 identifier. Nor is the surge the work of one project. The npm package openclaw accounts for 590 advisories on its own. Strip it out and 10,144 remain for the year, still 3.18 times the prior total.
Marcus Chen, writing in the same Axis report, argues the driver is discovery capacity rather than attacker activity. Automated analysis has reached the long tail of packages that no human researcher was going to audit. The bugs were already in dependency trees. What changed is that somebody finally looked. The operational consequence, he writes, is that a triage queue sized for the 369 advisories of December 2025 met 1,661 in May 2026, with no matching headcount increase in between.
Where the blind spots are
The CVE gap is the part that bites CVE-keyed tooling. Axis puts it at 1,273 advisories out of 10,734, or 11.9%. A scanner that only ingests CVE feeds therefore misses roughly one advisory in eight. Ecosystem-native feeds cover the difference. crates.io scores 46.9 on the Axis pressure index despite modest volume, because 39.8% of its advisories never get a CVE.
Axis also built an Open Source Ecosystem Pressure Index. It weights advisory volume at 35%, severity load at 25%, coverage gap at 20% and exploitation density at 20%, with each component max-scaled across eight ecosystems. As of 4 September the readings were npm 70.0, PyPI 59.2, Go 55.8, NuGet 51.1, Maven 48.3, Packagist 47.2, crates.io 46.9 and RubyGems 33.8.
Exploitation is still rare relative to volume. Of the 1,694 entries in CISA's Known Exploited Vulnerabilities catalog, 131 (7.7%) resolve to an open source package advisory. Among 2026 additions the share rises to 11.9%, 25 of 210. And 10 of those 25, 40.0%, are AI or ML packages: Langflow, LiteLLM, MLflow, Ray and Marimo. Across all prior years combined the figure was 3 of 106, or 2.8%.
Commercial codebase scans point the same direction. Black Duck's 2026 Open Source Security and Risk Analysis report, published 25 February and based on 947 commercial codebases across 17 industries, found the mean number of open source vulnerabilities per codebase more than doubled, up 107% to 581. 87% of audited codebases contained at least one vulnerability and 78% contained high-risk issues, with 44% carrying critical-risk findings.
The same report links the rise to AI-assisted development. The mean number of files per codebase grew 74% year over year and open source components per codebase rose 30%. Roughly 85% of organizations use AI-powered coding assistants, and 76% of companies that explicitly prohibit those tools say developers use them anyway. Black Duck also flags maintenance debt: 93% of codebases contain components with no development activity in the last two years, and 92% contain components four or more years out of date.
Fixing, not just finding
CISA lists OSV, Google's vulnerability database and triage infrastructure for open source, among its no-cost cybersecurity tools. It notes the service requires a Google Cloud Platform and Google Group account. OSV aggregates databases that adopted the OSV schema, including GitHub Security Advisories, PyPA, RustSec and the Global Security Database, and exposes an API for querying by commit hash or package version.
OWASP is trying to attack the remediation side. It announced the Open Automated Security Initiative for Software, OASIS, on 26 August 2026 in San Francisco, according to Cyber Security News. The initiative pairs AI-generated fix candidates with human validation from AppSec practitioners, then submits vetted patches upstream. Founding sponsors are AppSecAI, Intigriti and DryRun Security. The report cites the Black Duck 2026 OSSRA figure that open source underlies roughly 98% of commercial codebases.
The initiative is positioned as complementary to enterprise-led efforts including OpenAI's Patch the Planet, the Linux Foundation's Akrites and Anthropic's Project Glasswing, which concentrate elite research teams on operating systems and browsers. OASIS instead leans on volunteer reviewers to cover the long tail of libraries. David Kosorok, director of product security at ACV Auctions, is quoted calling that the highest-leverage work in application security. His argument: one validated upstream fix can secure thousands of downstream applications.
What none of this changes is the arithmetic facing a security team. Advisory volume grew 3.36-fold in a year. Headcount did not.
Sources
5- 01Open Source Vulnerability Statistics 2026: Advisory Volume, Ecosystem Exposure, and Confirmed ExploitationEN
- 022026 OSSRA Report: Open Source Vulnerabilities Double as AI SoarsEN
- 03OWASP Launches OASIS AI Initiative to Fix Open Source Vulnerabilities at ScaleEN
- 04Open Source Vulnerabilities (OSV) | CISAEN
- 05OSV - Open Source VulnerabilitiesEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.