What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The “3%” figure is a finding attributed to ShiftLeft’s 2022 AppSec Progress Report—not a census showing that 97% of open-source vulnerabilities are harmless. It describes the report’s studied context, as covered by Dark Reading in 2022. Its useful lesson is narrower: a vulnerable library in an application does not automatically mean an attacker can reach the affected code. Reachability can help prioritize investigation, but it is not proof that an unflagged issue is safe to ignore.
What did the 3% figure measure?
Dark Reading reported that ShiftLeft’s 2022 AppSec Progress Report found 3% of the open-source software bugs considered in its context to be “attackable.” The article also reported the company’s claim that considering attackability reduced false-positive library-upgrade tickets by 97%. These are report findings, not independently established rates that every organization should expect. The coverage does not establish a universal population of open-source bugs or a method that would make the percentage a timeless estimate of real-world exploitation. Dark Reading’s June 24, 2022 coverage
“Attackable” is not the same as “has been exploited.” The central question is whether an attacker can reach the vulnerable code path in the specific application and under its actual conditions. A dependency’s presence in an inventory, or an alert about its vulnerability, does not by itself answer that question.
What does reachability analysis tell you?
Reachability analysis examines whether application execution can access a vulnerable method or code path. If a vulnerable function is not called or otherwise accessible in the application context, that can be useful evidence for ordering remediation work. It does not establish that the entire dependency is safe, that every execution path was found, or that attackers cannot exploit the issue through another route.
#1 Best Overall
Mark Curphey, identified by Dark Reading as OWASP’s founder, said that most vulnerable methods in open-source libraries cannot be reached and therefore are not exploitable, while warning that libraries expose many functions for developers to use. He also pointed to Log4Shell as a reminder that paths used by relatively few people can still become exploitable. The point is not that reachability is useless; it is that uncommon or overlooked paths should not be dismissed solely because they seem unlikely to be used. Dark Reading
How should teams weigh a vulnerability alert?
| Signal or approach | What it helps answer | Important limitation |
|---|---|---|
| Dependency presence or severity-only alert | Whether an identified component is associated with a reported vulnerability, and how severe that vulnerability is assessed to be. | It does not establish whether vulnerable code is reachable in the application. |
| Reachability analysis | Whether the application’s analyzed code paths appear to reach the vulnerable functionality. | Its usefulness depends on dependency discovery, analysis coverage, and the quality of vulnerability intelligence feeding it. Dark Reading |
| Evidence of active exploitation, such as CISA KEV catalog inclusion | Whether there is evidence that a vulnerability is being exploited in the wild. | It is a prioritization signal, not a substitute for checking applicability, exposure, or remediation requirements. CISA describes the catalog as a living list. CISA’s June 9, 2022 notice |
Inventory scope matters. A declared dependency manifest may not tell the whole story if deployed components or artifacts are missed. Dark Reading’s quoted experts cautioned that the depth and quality of dependency tracking affect findings. Vulnerability intelligence matters too: reachability analysis cannot compensate for an incomplete or inaccurate feed. Dark Reading
Rank #2
What should security and development teams do?
- Confirm the component and vulnerability. Check that the affected dependency or artifact is actually present in the relevant application or deployment, and verify the vulnerability information against reliable intelligence.
- Check applicability and reachable paths. Determine whether the affected functionality is used or accessible in the application. Treat analysis results as evidence for triage, not as a guarantee that unflagged vulnerabilities are harmless.
- Escalate active-exploitation evidence. Check whether the issue appears in CISA’s Known Exploited Vulnerabilities catalog or is otherwise known to be actively exploited. CISA says the catalog is based on evidence of active exploitation and urges organizations to prioritize timely remediation. Its binding remediation directive applies to U.S. federal civilian executive branch agencies; it is not the same legal mandate for every organization. CISA
- Patch in context. Balance reachability findings with exploitation evidence, exposure, severity, and applicable obligations. Do not use a low aggregate percentage to defer a vulnerability that affects your system or has evidence of exploitation.
A joint-agency advisory released by NSA on August 3, 2023, reported that malicious actors exploited known vulnerabilities during 2022, including some that had been known for more than five years. The agencies recommended immediate patching of the listed routinely exploited vulnerabilities. That history supports prioritizing known exploitation; it does not establish that every vulnerability is exploited or that every listed issue applies to every system. NSA’s advisory announcement
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What reachability analysis does not cover
Reachability is one way to prioritize ordinary vulnerabilities in software components. It does not address every software-supply-chain threat. In particular, analysis of whether an application reaches a vulnerable method is not a check for a malicious package intentionally published to attack its users. Those risks require controls beyond vulnerability triage.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Best Value
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

