A year of open source vulnerability trends: CVEs, advisories, and malware

2026-03-26T19:23:29Za4d447331ec71d8dc9b9769b081b27cbfdc56d1758c980e4bd7f4ae52bc787b9
AI-detectionsCNAsCodeQLadvisoriesapplication-securitybug-bountyfuzzingmaintainer-supportmalwareopen-sourcesecurity-labsupply-chain-securitytaskflow-agentvulnerability-trendsvulnerability-triage

What happened

Collection of GitHub Security Blog posts (late 2025–2026) covering open source vulnerability trends and defenses: reviewed advisories hit a four‑year low while malware advisories surged and CNA publishing increased; GitHub expanded application security using CodeQL plus AI‑powered detections across more languages and frameworks; GitHub Security Lab released the Taskflow Agent (an open‑source AI‑powered framework) to improve scanning and AI‑assisted triage for high‑impact issues (auth bypass, IDOR, token leaks, etc.); guidance on supply‑chain malware preparedness, continuous fuzzing limitations

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
github_security_blog
Record identifier
a4d447331ec71d8dc9b9769b081b27cbfdc56d1758c980e4bd7f4ae52bc787b9
Enrichment time
2026-03-26T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.