I just published something I've been wanting to share for a while! Earlier this year, our team published a deep dive into open source vulnerability trends across 2025. But the data through December only told part of the story.
In Q1 2026, private vulnerability reports submitted to maintainers on GitHub increased over 4x. The number of unique reporters doubled. The number of targeted repositories doubled. No single reporter, project, or organization is driving it - this is a systemic shift.
Here's what surprised me most: despite the volume surge, CVE requests to our CNA nearly quadrupled and our assignment rate actually improved - from ~90% to ~93%. The increase isn't just noise. Real vulnerabilities are being found, disclosed, and published faster than ever.
But the pressure on maintainers is real. Acceptance rates have dipped. Backlogs are growing. And the people who maintain the software the world runs on are absorbing more of the burden every quarter.
I wrote up the full analysis - the data, the nuance, and what we're doing about it - in the article below.
If you're a maintainer, a security researcher, or someone who cares about the sustainability of open source: I'd love to hear what you're seeing on your side.
#opensource #cybersecurity #vulnerabilitymanagement