The Headline Numbers
97% of the codebases audited contained open source software. The average codebase was 78% open source by volume — only 22% was custom-written code. 81% of codebases contained at least one known open source vulnerability. 49% contained high-risk vulnerabilities — those with a CVSS score of 7.0 or higher. The median age of vulnerabilities found was over two years, meaning patches had been available for years in most cases.
The License Risk Picture
53% of codebases contained open source with license conflicts — components whose licenses were incompatible with the codebase's intended distribution model. GPL and other copyleft licenses were present in 45% of codebases — in many cases without the development teams being aware of the license implications.
Industry Variation
Some industries showed dramatically higher vulnerability rates. Enterprise software had the highest proportion of high-risk vulnerabilities. IoT and embedded systems showed the highest percentage of components that had not been updated in more than four years — a significant concern given that many of these devices have long deployment lifetimes and limited patch mechanisms. Financial services showed lower overall vulnerability counts but higher rates of copyleft license risk, potentially reflecting legal teams' stricter scrutiny of security issues versus license issues.
The M&A Due Diligence Lens
The fact that these audits are conducted during M&A due diligence makes the findings particularly significant. These are not random samples — they are codebases being scrutinized by acquirers. The data suggests that even companies sophisticated enough to be M&A targets carry significant open source risk that was not visible during their normal development operations. The implication for any software organization is that if your codebase were audited tomorrow, it would likely show similar patterns.
Know What Your Codebase Contains — Before an Audit Does
Fossity — Fossity gives you the same component visibility that M&A due diligence audits provide — without waiting for an acquisition to trigger it. Continuous SBOM generation and vulnerability monitoring means no surprises when external scrutiny arrives.
Visit Fossity.com →