{"id":35766,"date":"2020-06-26T14:34:06","date_gmt":"2020-06-26T14:34:06","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31337\/More-Than-75-Of-All-Vulnerabilities-Reside-In-Indirect-Dependencies.html"},"modified":"2020-06-26T14:34:06","modified_gmt":"2020-06-26T14:34:06","slug":"more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/","title":{"rendered":"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies"},"content":{"rendered":"<p>The vast majority of security vulnerabilities in open-source projects reside in indirect dependencies rather than directly and first-hand loaded components.<\/p>\n<p>&#8220;Aggregating the numbers from all ecosystems, we found more than three times as many vulnerabilities in indirect dependencies than we did direct dependencies,&#8221; <a href=\"https:\/\/twitter.com\/AlyssaM_InfoSec\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Alyssa Miller<\/a>, Application Security Advocate at Snyk, told <em>ZDNet<\/em> in an interview discussing Snyk&#8217;s State of Open Source Security for 2020 study.<\/p>\n<p>The report looked at how vulnerabilities impacted the JavaScript (npm), Ruby (RubyGems), Java (MavenCentral), PHP (Packagist), and Python (PyPI) ecosystems.<\/p>\n<p>Snyk said that 86% of the JavaScript security bugs, 81% of the Ruby bugs, and 74% of the Java ones impacted libraries that were dependencies of the primary components loaded inside a project.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2020\/06\/26\/37fd4cbc-49c4-4788-9738-2442a67ab2a3\/snyk-indirect.png\" class alt=\"snyk-indirect.png\"><\/span> <span class=\"credit\">Image: Snyk<\/span><\/p>\n<p>Snyk argues that companies scanning their primary dependencies for security issues without exploring their full dependency tree multiple levels down would release or end up running products that were vulnerable to unforeseen bugs.<\/p>\n<p>But while security bugs were prevalent in JavaScript, Ruby, and Java, it was not in PHP and Python, where the vast majority of bugs were in the direct dependencies (primary components). However, there&#8217;s a reason for that.<\/p>\n<p>&#8220;I honestly find it&#8217;s more a matter of the development approach within ecosystems themselves,&#8221; Miller told <em>ZDNet<\/em>.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>&#8220;Java and Node.js projects, in particular, seem to leverage dependencies a lot heavier than other ecosystems. In particular, when you look at the sheer size of the Node.js ecosystem, packages building off or leveraging key functionality from other packages is very much the norm.<\/p>\n<p>&#8220;Ask any Node developer, and they probably have a story of waiting for long periods to open a project while npm is trying to pull all the necessary dependencies,&#8221; Miller added. &#8220;One of our favorite examples is an 80 line Java application that specifies 7 dependencies. When you walk the entire dependency tree, however, you find 59 sub-dependencies, and suddenly, the 80 lines of code turns into 740,000 lines.<\/p>\n<p>&#8220;That &#8216;stranger danger,&#8217; as we like to nickname it, is at the heart of some high profile breaches and a key cause of complexity in terms of software supply chain security,&#8221; Miller said.<\/p>\n<h3>A few bugs had a large impact<\/h3>\n<p>But the Snyk team didn&#8217;t just look at the location of these bugs in the open-source ecosystem, but also at what type of bugs they were.<\/p>\n<p>Another interesting finding is that most of the new security flaws discovered in 2019 were cross-site scripting (XSS) bugs, but despite their high number, these impacted only a small portion of real-world projects.<\/p>\n<p>Instead, two-dozen prototype pollution bugs had the biggest impact of all bugs discovered last year, affecting more than 115,000 different open source projects, and probably even more private ones.<\/p>\n<p>Of these, the prototype pollution bugs in <a href=\"https:\/\/www.zdnet.com\/article\/popular-jquery-javascript-library-impacted-by-prototype-pollution-flaw\/\" target=\"_blank\" rel=\"noopener noreferrer\">jQuery<\/a> and <a href=\"https:\/\/snyk.io\/vuln\/SNYK-JS-LODASH-450202\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">LoDash<\/a> had the biggest impact, as these frameworks are some of the most widely employed JavaScript development toolsets today.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/\" class=\"lazy\" alt=\"snyk-vuln-impact-type.png\" data-original=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2020\/06\/26\/5094bbd7-656c-4266-9335-17a8c3156089\/snyk-vuln-impact-type.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2020\/06\/26\/5094bbd7-656c-4266-9335-17a8c3156089\/snyk-vuln-impact-type.png\" class alt=\"snyk-vuln-impact-type.png\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Snyk<\/span><\/p>\n<p>But the Snyk team also pointed to another quirck in their report, namely that &#8220;malicious packages&#8221; ranked as the second most common type of security issue they found in projects last year.<\/p>\n<p>This refers to open-source libraries that have either been created to be malicious on purpose, or libraries where the developer account was hacked and the code poisoned.<\/p>\n<p>According to Snyk, last year, hacked or malicious packages were the second most common source of security issues for the open-source ecosystem.<\/p>\n<p>&#8220;The vast majority, over 87%, were from npm [JavaScript] packages,&#8221; Miller told <em>ZDNet<\/em>.<\/p>\n<h3>Fewer security bugs last year, but no reason to celebrate<\/h3>\n<p>Furthermore, Snyk also noted a 20% drop in the number of bugs they discovered across all the five ecosystems they scanned.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/\" class=\"lazy\" alt=\"snyk-vuln-2019.png\" data-original=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2020\/06\/26\/03eaa4dd-0803-4a09-a5bf-ddda4e13c48d\/snyk-vuln-2019.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2020\/06\/26\/03eaa4dd-0803-4a09-a5bf-ddda4e13c48d\/snyk-vuln-2019.png\" class alt=\"snyk-vuln-2019.png\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Snyk<\/span><\/p>\n<p>&#8220;It is hard to say for sure [why they dropped],&#8221; Miller said. &#8220;The perpetual security skeptic in me says this could just be part of the natural ebb and flow. However, on the optimistic side, we do see some key shifts in the community that could mean it&#8217;s more than just a single year outlier.<\/p>\n<p>&#8220;For instance, where we saw more Cross-Site Scripting (XSS) vulnerabilities reported than any other vulnerability type, they affected a small portion of the total projects we scanned for the year. That suggests that XSS is likely not impacting more heavily used and therefore matured projects meaning that we are potentially getting traction in secure coding techniques.<\/p>\n<p>&#8220;Also, our survey showed that attitudes across the community are starting to see software security as a shared responsibility between developers and security teams (and even to some extent the operations teams),&#8221; Miller said.<\/p>\n<p>&#8220;That improved cooperation could certainly be helping drive better awareness and tactical measures around secure code and secure use of open source packages.<\/p>\n<p>&#8220;Having worked in security for 15 years, I&#8217;m certainly not ready to proclaim one year as a sign that things have taken a new direction, but you can bet it&#8217;s a trend we&#8217;ll continue to watch and see how things look over the coming months and the whole of 2020.&#8221;<\/p>\n<p>For additional insights into the general security state of the open-source community, Snyk&#8217;s full report is available for download <a href=\"https:\/\/info.snyk.io\/sooss-report-2020\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">here<\/a>.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31337\/More-Than-75-Of-All-Vulnerabilities-Reside-In-Indirect-Dependencies.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":35767,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[968],"class_list":["post-35766","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlineflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-26T14:34:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"457\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies\",\"datePublished\":\"2020-06-26T14:34:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/\"},\"wordCount\":851,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png\",\"keywords\":[\"headline,flaw\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/\",\"name\":\"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png\",\"datePublished\":\"2020-06-26T14:34:06+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png\",\"width\":770,\"height\":457},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlineflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/","og_locale":"en_US","og_type":"article","og_title":"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-06-26T14:34:06+00:00","og_image":[{"width":770,"height":457,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies","datePublished":"2020-06-26T14:34:06+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/"},"wordCount":851,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png","keywords":["headline,flaw"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/","url":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/","name":"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png","datePublished":"2020-06-26T14:34:06+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies.png","width":770,"height":457},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/more-than-75-of-all-vulnerabilities-reside-in-indirect-dependencies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlineflaw\/"},{"@type":"ListItem","position":3,"name":"More Than 75% Of All Vulnerabilities Reside In Indirect Dependencies"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=35766"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35766\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/35767"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=35766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=35766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=35766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}