Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Almost half of the audited applications in Synopsys’s 2023 Open Source Security and Risk Analysis (OSSRA) report contained high-risk open-source vulnerabilities. The reported share was 48%—down from about 60% in the 2020 findings. That is a result for audited commercial and proprietary codebases, not a measurement of every application currently deployed.

The same report found that 84% of assessed codebases contained at least one known open-source vulnerability. “High-risk” and “any known vulnerability” are different categories, so the figures should not be combined or treated as interchangeable.

What the “half of apps” figure actually measures

Synopsys published the eighth OSSRA report on February 22, 2023. It analyzed more than 1,700 audits associated with commercial and proprietary codebases across 17 industries; 1,480 codebases received risk assessments. These audits are commonly performed in merger-and-acquisition due diligence and related business reviews.

Within that sample, 48% of applications had at least one vulnerability classified as high risk. Dark Reading reported that the comparable share was about 60% in 2020. The result describes the report’s audited sample and classification method. It is not a random census, a live 2026 estimate, or proof that every finding was exploitable in the same way.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The important numbers, kept separate

Measure 2023 OSSRA finding What it means
Applications with high-risk open-source vulnerabilities 48% At least one finding in the report’s high-risk category
Codebases with any known open-source vulnerability 84% A broader category that includes vulnerabilities not classified as high risk
Applications containing open-source components 96% Open source was present in nearly all audited applications
Open-source share of the average codebase 76% The average audited codebase consisted predominantly of open-source code
Average components per application 595 Up 13% from 528 in the prior year, according to Synopsys
Risk-assessed codebases with outdated component versions 91% of 1,480 A maintenance and patching indicator, not a statement that every outdated component was exploitable
Applications with a component showing no development in the prior two years 91% A possible maintenance signal; inactivity alone does not prove abandonment or vulnerability
Codebases using components with no discernable or customized licenses 31% A license-compliance risk measure, not a vulnerability rate

Why open-source dependency volume matters

Modern applications rarely consist only of code written by the organization that ships them. Frameworks, libraries, build tools, containers and transitive dependencies can create a large software supply chain. A direct dependency may bring in several indirect dependencies, each with its own version history, maintainers and security advisories.

Synopsys reported an average of 595 open-source components per application in 2023. More components create more items to identify, track and patch. Mike McGuire, a senior software solutions manager at Synopsys Software Integrity Group, summarized the operational problem: “Organizations are struggling to keep up with the scale of open source usage.” He also said, “More organizations are using more open source components, but they just don’t have the programs in place to track those [patches] down.”

The report does not say that open source is inherently unsafe. Its stated position is: “It is crucial to understand that while open source itself does not pose any inherent level of risk, failing to manage it does.” Risk depends on factors such as exposure, exploitability, affected versions, compensating controls and how quickly an organization can remediate a relevant issue.

High-risk findings versus any known vulnerability

High-risk: 48%

This is the headline measure. It counts applications in the audited sample with at least one vulnerability that the report classified as high risk. The classification is not a claim that all vulnerabilities in those applications were equally severe or remotely exploitable.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Any known vulnerability: 84%

This broader figure includes known vulnerabilities outside the high-risk category. A codebase can therefore be included in the 84% figure without being included in the 48% figure. Reporting the two percentages as if they describe the same condition exaggerates or distorts the finding.

Maintenance signals: old and inactive components

In 91% of the 1,480 risk-assessed codebases, Synopsys found outdated open-source component versions. Separately, 91% of applications contained at least one component with no development in the preceding two years. These numbers indicate how difficult dependency maintenance can be, but neither is a direct vulnerability verdict.

An older version may be unaffected by a particular vulnerability, may be protected by the way the application uses it, or may be awaiting a tested upgrade. Conversely, a recently updated project can still contain a newly disclosed flaw. Teams need component-level analysis rather than a rule that treats every old or inactive project as unsafe.

Where open-source use and high-risk trends changed

Synopsys reported substantial five-year changes in particular sectors. EdTech open-source adoption grew 163%, which the report partly associated with the expansion of online education during the pandemic. Open-source use increased 97% in Aerospace, Aviation, Automotive, Transportation and Logistics, and 74% in Manufacturing and Robotics.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report also described increases in high-risk vulnerabilities since 2019 in selected sectors: 557% in Retail and eCommerce, 130% in IoT, and 232% in Aerospace, Aviation, Automotive, Transportation and Logistics. These are sector-specific trend figures, not cross-industry prevalence rates and not evidence that one sector’s percentage applies to all applications.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations should do with the finding

1. Build a complete software inventory

Create and maintain a software bill of materials (SBOM) covering direct and transitive components. Record each component’s name, version, source, license and relationship to the application. An SBOM provides visibility; it does not, by itself, remove vulnerabilities.

2. Track versions and patch status

Connect inventory records to vulnerability advisories and internal ownership. When a component is affected, determine whether the deployed version is in scope, whether the vulnerable code path is used, and whether an upgrade or compensating control is practical.

3. Prioritize findings by real exposure

Use severity together with exploit availability, internet exposure, reachable functionality, business criticality and available fixes. This prevents teams from treating every advisory, outdated package or inactive project as an identical emergency.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Add dependency controls to the delivery process

Use lockfiles or equivalent version pinning, review new dependencies, scan builds and containers, and set ownership for remediation. Recheck the inventory when releases change; a one-time SBOM quickly becomes stale.

5. Include license review

Because 31% of codebases used components with no discernable license or customized licenses, security review should be paired with license identification and legal escalation. License ambiguity is a separate supply-chain risk from a known software vulnerability.

How to read the 2023 result today

The 48% statistic remains a historical finding from the 2023 OSSRA analysis. It supports a clear conclusion about the audited sample: high-risk open-source vulnerabilities were common, while open-source components were nearly universal. It does not establish the prevalence of vulnerabilities in all software in 2026. A current rate would require a newer, comparably scoped audit.

Jason Schmitt, general manager of the Synopsys Software Integrity Group, described a comprehensive SBOM listing components, licenses, versions and patch status as “a foundational strategy towards understanding and reducing business risk by defending against software supply chain attacks.” The practical lesson is not to avoid open source, but to know what is in each application and manage it continuously.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

The 2023 OSSRA report found high-risk open-source vulnerabilities in 48% of audited applications, while 84% had at least one known open-source vulnerability. Those historical sample-based figures show why dependency inventory, version tracking and risk-based remediation matter—but they are not a current universal rate for every app.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.