AI Briefing
KO

Open Source Vulnerability Trend Analysis: CVEs, Advisories, and Malware

·2026.03.27 01:00

Key point

The decline in GitHub's reviewed advisories in 2025 is not the result of fewer new vulnerabilities, but of a reduced share of past vulnerabilities being reviewed.

1 / 2

Details

GitHub published 4,101 reviewed advisories in 2025. This is the lowest figure since 2021, but it does not mean that the security of open source code has improved.

Actual data shows that newly reported vulnerabilities increased 19% year-over-year. The drop in the number of advisories occurred because GitHub reduced its backfill work of reviewing old, past vulnerabilities.

The key characteristics of the 2025 advisory ecosystem distribution are as follows:

  • Maven (22.24%), Composer (19.40%), Pip (17.16%), and npm (14.92%) accounted for the largest shares, in that order.
  • The Go ecosystem came in 6% higher than the overall database average, due to the impact of an internal review campaign.

Many of the advisories classified as unreviewed in the database have actually already been reviewed by curators, but were found not to affect a supported ecosystem, and so did not reach the formal review stage.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.