Cyber Posture

A03:2025 Software Supply Chain Failures

OWASP Top 10:2025 · Back to the list

Vulnerable, outdated, or compromised dependencies, build pipelines, and signing infrastructure. Expanded from 2021's 'Vulnerable and Outdated Components'.

Related on the LLM side: OWASP Top 10 for LLMs LLM03:2025.

Member CWEs (6)

Tagged CVEs (showing 50 most recent of 42)

Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1438).