A year of open source vulnerability trends: CVEs, advisories, and malware
Blog post from GitHub
In 2025, GitHub reported a decrease in the number of reviewed advisories, totaling 4,101, the lowest since 2021, but this did not correlate with fewer vulnerabilities being reported. Instead, the decrease was due to a reduction in the review of older advisories, while newly reported vulnerabilities saw a 19% increase in reviews. The GitHub Advisory Database, established in 2019, continues to play a crucial role in identifying security vulnerabilities, with notable changes in the types of vulnerabilities reported, such as an increase in resource exhaustion and unsafe deserialization issues. The year also saw a 69% rise in npm malware advisories due to large-scale malware campaigns and a 35% increase in published CVE records by GitHub's CVE Numbering Authority (CNA), highlighting the growing engagement of organizations in reporting vulnerabilities. Moreover, there was a significant improvement in CWE tagging, enhancing the specificity and actionability of data for remediation. GitHub encourages developers to participate in this ecosystem by using CNA services, contributing to advisory accuracy, and protecting their projects through tools like Dependabot, aiming for greater security advancements in 2026.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.