The findings, unveiled in Synopsys’ ninth annual Open Source Security and Risk Analysis (OSSRA) report, expose a troubling escalation in high-risk vulnerabilities within commercial codebases.
Through looking at over 1,000 commercial database audits across 17 industries, the report paints a stark picture, where about three quarters (74%) of commercial codebases harbour open source components plagued by high-risk vulnerabilities, jumping from 48% the previous year.
The data suggests instability and resource constraints might have contributed to the spike, as organisations grapple with intensified pressure to accelerate software development amid shrinking budgets.
“This year’s OSSRA report indicates an alarming rise in high-risk open source vulnerabilities across a variety of critical industries, leaving them at risk for exploitation by cybercriminals,” said Jason Schmitt, general manager at Synopsys Software Integrity Group.
“The increasing pressure on software teams to move faster and do more with less in 2023 has likely contributed to this sharp rise in open source vulnerabilities. Malicious actors have taken note of this attack vector, so maintaining proper software hygiene by identifying, tracking and managing open source effectively is a key element to strengthening the security of the software supply chain.”
The report also unearthed a pervasive reliance on outdated or inactive open source components, with 91% of codebases containing components that were 10 or more versions behind. Nearly half (49%) of codebases featured components devoid of development activity over the past two years.
Recommended reading
- Technology Heavyweights Create Open Source “AI Alliance”
- Could Cybersecurity Monoculture Affect Your Organisation?
- Web Apps Are Easy Targets in Ongoing Vulnerability Crisis
The Computer Hardware and Semiconductors industry also emerged as the most vulnerable, with 88% of codebases housing high-risk open source vulnerabilities. Manufacturing, industrials, and robotics followed closely behind, with 87% of codebases affected. Even industries such as big data, AI, BI, and machine learning experienced significant vulnerability rates, with 66% of codebases impacted by high-risk vulnerabilities.
Licence compliance also remained a persistent challenge, with over half (53%) of codebases grappling with open source licence conflicts. Furthermore, 31% of codebases utilised code with either no discernible licence or a customised licence, potentially exposing organisations to legal and intellectual property risks.
FInally, eight of the top 10 vulnerabilities traced back to one common weakness type, which is classified as Improper Neutralisation weaknesses (CWE-707), encompassing various forms of cross-site scripting. This vulnerability type poses severe risks if exploited, underscoring the urgent need for comprehensive vulnerability management strategies.





