Open-source vehicle software faces major vulnerability risk as EU CRA deadline nears
More than half of the open-source software stack behind software-defined vehicles contains known vulnerabilities, according to a new benchmark from DerScanner. The findings land two days before key EU Cyber Resilience Act obligations take effect, raising the stakes for automakers and suppliers shipping products into the European market.
Why it matters: - More than half of the open-source software stack behind software-defined vehicles carries a known security flaw. - The EU Cyber Resilience Act starts applying to manufacturers placing products on the EU market in two days, on 11 September 2026. - Under those rules, actively exploited vulnerabilities must be reported within 24 hours. - Penalties can reach 15 million euro or 2.5% of worldwide annual turnover, whichever is higher. - Automotive companies now face supply chain hygiene as a compliance issue, not just an engineering issue.
What happened: - DerScanner benchmarked 43 open-source components from the Eclipse SDV, KUKSA, COVESA and Velocitas projects. - The scan resolved 8,821 dependencies across those components. - The benchmark found that 55% of resolved dependencies carry a known vulnerability. - Those dependencies accounted for 660 distinct CVEs, including 333 critical CVEs. - At least one critical finding appeared in 30 of the 43 components.
The details: - The same codebases also contained 826 packages that generated no CVE but still posed risk. - Of those packages, 671 were abandoned with zero maintenance activity. - Another 311 were starjacking a more popular project. - A further 124 were typosquatting a well-known package name. - Thirty packages survived on a single maintainer. - Eighteen packages had a version documented to have shipped malicious code. - The affected package set included debug, mongodb and jsdom, which are used widely across software projects.
Between the lines: - The hardest-to-spot risk sits below the manifest level, in dependencies engineers did not directly choose. - A manifest review shows the libraries developers intentionally added, while the dangerous code often lives deeper in the tree. - The findings suggest that software-defined vehicles inherit supply chain exposure from the broader open-source ecosystem, not just from their own code. - Black Duck reported that 65% of organizations surveyed in 2025 experienced a software supply chain attack in the prior year. - OWASP's Top 10 for 2025 added Software Supply Chain Failures as a Top 3 category, and half of community survey respondents ranked it first.
What's next: - Manufacturers shipping into the EU market will need to identify, report and remediate actively exploited vulnerabilities under the CRA timeline. - The benchmark implies that dependency review, package provenance checks and maintenance monitoring will become more important for automotive software teams. - The pressure will likely extend beyond automotive as the same open-source patterns affect many software supply chains.
The bottom line: - The new benchmark shows a high vulnerability burden in the code underpinning software-defined vehicles just as EU compliance deadlines begin to bite.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
European News Update
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.