Confronting today’s open source security challenges

Open source dominates modern software because it speeds up development, but open source vulnerabilities now outpace remediation. Organizations face a dilemma: live with the risk, or spend considerable engineering time understanding and fixing each vulnerability. Seal Security researched how organizations manage open source vulnerabilities, the limits of Software Composition Analysis (SCA) and prioritization tools, and where automation helps.
Key findings
- 99% of CVE fixes can be backported. Of the vulnerable libraries analyzed over two years, 90.5% were fixed in a patch version, 8.4% in a minor version and only 1.1% in a major version.
- 62% of vulnerabilities were fixed in a later major version than the one in which they were introduced, so upgrading to get the fix often means jumping major versions and absorbing breaking changes.
- 61% of npm packages in use are not on the latest version, 53% are not on the latest minor version and 40% are not on the latest major version.
- Up to 30% of vulnerabilities in transitive dependencies have no fix or no clear upgrade path.
- Teams spend 2-5% of developer time on security-driven upgrades, and some large enterprises spend as much as 10%.
- Only critical vulnerabilities reliably trigger upgrades. 40% of downloads of packages with no critical vulnerabilities are not on the latest major version; that drops to 9% with one critical vulnerability and under 0.5% with two or more. High-severity vulnerabilities barely change behavior (63% vs 75% stay on an old major version).
- Old versions do not accumulate vulnerabilities without limit. Across 2,312 npm libraries, the average version has 1.5 known vulnerabilities, 0.07 of them critical, so a finite set of security patches is usually enough to secure an old version.
Why open source vulnerability remediation is so hard
- Vulnerability overload and skills gaps: thousands of vulnerabilities across business units, while the R&D teams responsible for fixing them lack incentives to do the work.
- Legacy code: old, unmaintained codebases full of vulnerable libraries where any significant upgrade is risky and pulls resources from the core business.
- Unpatched transitive dependencies: often no clear upgrade path, which drags out risk assessments.
- Operational risk: upgrades can trigger serious production incidents; Datadog suffered a multi-million-dollar, multi-region outage following an update.
- Legal risk: newer library versions sometimes ship under different licenses.
- End-of-life software: the end of CentOS updates in June 2024 and Python libraries dropping Python 2 both force daunting migrations.
- Attackers targeting automated version bumps: the event-stream attack showed how unverified automatic updates can deliver malware.
The limits of SCA and prioritization tools
More than 60% of organizations rely on SCA and prioritization tools to keep third-party libraries patched. These tools identify vulnerabilities and suggest upgrades, but they are blind to the risk and effort of those upgrades, they generate false positives because reachability and exploitability are hard to verify, and prioritization does not remediate anything. An ESG-Mend study found that even the 40% of organizations that prioritize effectively still struggle to remediate. Snyk data shows 38% of organizations fix half or fewer of the vulnerabilities they find, and 10% fix less than a quarter.
The role of AI-driven automation
AI and automation can deliver security patches quickly, support code analysis and keep older code secure and compliant with standards such as FedRAMP and NYDFS Part 500. They also make post-end-of-life support feasible by patching operating systems and frameworks after upstream support ends. Seal Security applies this approach to give security teams centralized control over open source vulnerability remediation, with standalone patches for direct and transitive dependencies that do not depend on upstream maintainers.
Sharing this with your team? Download the white paper as a PDF to pass along internally.
See it on your own stack
Seal Security backports security fixes into the open source versions you already run, across application dependencies, containers and Linux distributions, with no upgrade required.
See Seal on your stack
Get a walkthrough of how Seal backports security fixes into the open source versions you already run, with no upgrade and no code changes.
Book a demoChat with an expert
