<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/the-growing-risk-of-high-risk-open-source-vulnerabilities-in-codebases-c2kjf3fn9" -->

---
title: The Growing Risk of High-Risk Open Source...
description: A Synopsys report highlights a significant increase in high-risk open source vulnerabilities in commercial codebases. Many codebases depend on outdated...
canonical: https://daily.dev/posts/the-growing-risk-of-high-risk-open-source-vulnerabilities-in-codebases-c2kjf3fn9
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: The Growing Risk of High-Risk Open Source Vulnerabilities in Codebases | daily.dev
og:description: A Synopsys report highlights a significant increase in high-risk open source vulnerabilities in commercial codebases. Many codebases depend on outdated...
og:url: https://daily.dev/posts/the-growing-risk-of-high-risk-open-source-vulnerabilities-in-codebases-c2kjf3fn9
og:image: https://api.daily.dev/og/posts/c2kjf3fN9.png
og:image:alt: The Growing Risk of High-Risk Open Source Vulnerabilities in Codebases
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# The Growing Risk of High-Risk Open Source Vulnerabilities in Codebases

**[Collections](https://daily.dev/sources/collections)** · 1 min read · 2 upvotes · 0 comments

## Summary

A Synopsys report highlights a significant increase in high-risk open source vulnerabilities in commercial codebases. Many codebases depend on outdated components, and the computer hardware and semiconductor industry is the most vulnerable.

## Content

A recent report by Synopsys highlights a concerning trend in the prevalence of high-risk open source vulnerabilities in commercial codebases. The study reveals that in 2023, a staggering 74% of codebases assessed for risk contained components with high-risk vulnerabilities, indicating a significant 54% increase from the previous year. It is alarming to note that many codebases continue to depend on outdated or inactive open source components, with a striking 91% of codebases found to have components that were more than 10 versions out of date. The computer hardware and semiconductor industry appears to be the most vulnerable, with the highest percentage of high-risk open source vulnerabilities. One of the most prevalent types of vulnerabilities identified in the report were improper neutralization flaws. These findings emphasize the urgent need for organizations to proactively identify and address vulnerabilities in their codebases in order to mitigate the overall level of risk. Neglecting to patch these vulnerabilities could have severe consequences, potentially leading to data breaches and other security incidents. It is crucial for organizations to prioritize ongoing maintenance and updates of their open source components to ensure the security of their codebases and protect against potential threats.

## Similar posts on daily.dev

- [Governing Security in the Age of Infinite Signal](https://daily.dev/posts/governing-security-in-the-age-of-infinite-signal-qhihbir44) · Snyk · 0 upvotes · 0 comments
- [No one has a good plan for how AI companies should work with the government](https://daily.dev/posts/no-one-has-a-good-plan-for-how-ai-companies-should-work-with-the-government-nkajqoze1) · TechCrunch · 0 upvotes · 1 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#general-programming](https://daily.dev/tags/general-programming), [#open-source](https://daily.dev/tags/open-source), [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/the-growing-risk-of-high-risk-open-source-vulnerabilities-in-codebases-c2kjf3fn9)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"The Growing Risk of High-Risk Open Source Vulnerabilities in Codebases","url":"https://daily.dev/posts/the-growing-risk-of-high-risk-open-source-vulnerabilities-in-codebases-c2kjf3fn9","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/the-growing-risk-of-high-risk-open-source-vulnerabilities-in-codebases-c2kjf3fn9"},"datePublished":"2024-02-28T13:26:28.953Z","dateModified":"2026-03-15T06:49:58.729Z","description":"A Synopsys report highlights a significant increase in high-risk open source vulnerabilities in commercial codebases. Many codebases depend on outdated...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2b1c40de53c7d5850c85f62646c7c794?_a=AQAEufR","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2b1c40de53c7d5850c85f62646c7c794?_a=AQAEufR","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/the-growing-risk-of-high-risk-open-source-vulnerabilities-in-codebases-c2kjf3fn9","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,general-programming,open-source,security","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"The Growing Risk of High-Risk Open Source Vulnerabilities in Codebases"}]}
```

