Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Static vs. Runtime Reachability: Insights from Latio’s On th...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
411
Company Posts That Month
33
Language
English
Hacker News Points
-
Post removed?
No
Summary

Latio's "On the Record" podcast delves into the significance of static and runtime reachability in vulnerability management, highlighting their roles in prioritizing exploitable vulnerabilities and optimizing application security workflows. With the surge in vulnerability disclosures in 2025, understanding which vulnerabilities are truly relevant is crucial for saving time and resources. The episode features insights from Martin Torp of Socket and Omer Yair of Raven.io, who discuss how reachability helps focus on relevant CVEs, noting that not all reachable vulnerabilities are exploitable due to potential safeguards. The podcast explains static reachability as analyzing code without execution, beneficial for early triage, and runtime reachability as observing live applications for accurate results with minimal performance impact. By combining both approaches, teams can gain a comprehensive understanding of exploitable vulnerabilities, enhancing the efficiency of AppSec programs, with discussions extending to language support, function-to-CVE mapping, and compliance frameworks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.