Open Source Software: Security Principles and Practices
Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems. Visit CISA’s Open Source Security webpage for more resources. CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email opensource@cisa.dhs.gov . To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material. Please share your thoughts! We welcome your feedback. CISA Product Survey
CSIRTS triage
- What
- Guidance on securely using, evaluating, and publishing open source software.
- Who is affected
- Agencies and organizations using open source software.
- Urgency
- This guidance is critical for managing risks associated with open source software.
- Action
- Agencies should review and implement the recommended practices for open source software security.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices
Recent advisories for Open Source Software
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-67529: OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v…nvd · 2026-07-30
- mediumCVE-2026-67528: OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v…nvd · 2026-07-30
- highCVE-2026-67527: OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api…nvd · 2026-07-30
- mediumCVE-2026-64685: ImageMagick is free and open-source software used for editing and manipulating digital images.…nvd · 2026-07-30
- mediumCVE-2026-62946: ImageMagick is free and open-source software used for editing and manipulating digital images.…nvd · 2026-07-30
- mediumCVE-2026-62363: ImageMagick is free and open-source software used for editing and manipulating digital images.…nvd · 2026-07-30
More from CISA Cybersecurity Advisories
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalSchneider Electric IGSS2026-07-30
- criticalMikroTik RouterOS2026-07-30
- criticalCISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs2026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30