Open Source Vulnerabilities Plateau in 2025: New Threats Surge Despite Fewer Alerts
GitHub reviewed just 4,101 advisories in 2025, the lowest since 2021. Don't pop the champagne—new vulnerabilities jumped 19%, and npm malware spiked 69%.
DevTools FeedApr 02, 20264 min read
⚡ Key Takeaways
Reviewed advisories hit 4,101 in 2025 (lowest since 2021), but new vulnerabilities rose 19%.𝕏
CWE-79 (XSS) still #1; resource exhaustion and deserialization climbed fast.𝕏
npm malware advisories up 69%; Go ecosystem overrepresented by 6%.𝕏
The 60-Second TL;DR
Reviewed advisories hit 4,101 in 2025 (lowest since 2021), but new vulnerabilities rose 19%.
CWE-79 (XSS) still #1; resource exhaustion and deserialization climbed fast.
npm malware advisories up 69%; Go ecosystem overrepresented by 6%.