Lightwell project filters out 400 Java library vulnerabilities

Lightwell, the open-source security initiative set up by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely used Java libraries — and now the companies are inviting customers to submit their own code dependencies to a new service, Lightwell Clearinghouse, for review.

They’ll be looking for bugs such as the critical sandbox bypass in Java template engine Thymeleaf, with a CVSS score of 9.1, discovered in April.

“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move,” said Gunnar Hellekson, vice president and general manager of Lightwell.

Source link

spot_img
spot_img

Leave a reply

Please enter your comment!
Please enter your name here