BENCHMARK REPORT · 2026
The Hidden Attack Surface of Automotive Software
We scanned 43 open-source components from the software-defined vehicle ecosystem across two axes of risk: known vulnerabilities and supply-chain trust. 55% of dependencies carried a CVE — and 826 packages carried a trust risk with no CVE at all.
A reproducible, dependency-level benchmark for security, product-security and compliance teams working under UN R155, ISO/SAE 21434 and the EU Cyber Resilience Act.
Your vehicle's real attack surface isn't the code you wrote.
Modern vehicles are assembled, not authored. 80 to 90% of a typical codebase is open-source and third-party code, pulled in through dependency trees most teams never fully map. That inherited code carries the exposure, not the software an OEM or supplier writes.
We measured it directly. Not a survey, not opinion: SCA and supply-chain trust scoring across 43 real automotive open-source components from Eclipse SDV / KUKSA, COVESA and Velocitas. Every finding is reproducible from public sources.
What we found
of resolved dependencies carried a known vulnerability. Vulnerable dependencies are the majority in this ecosystem, not the exception.
distinct packages carried a trust risk with no CVE: abandoned, starjacking, typosquatting, single-maintainer, or known malware. A clean scan is not safety.
unique critical CVEs per npm component on average — versus 2.3 in Rust. Density follows the ecosystem; every ecosystem was exposed.
No component can be assumed safe — on either axis.
Critical risk is structural, not random.
Inside the full report
- Named component rankingAll 43 components ranked by unique critical CVEs, with severity breakdown and trust-flagged package counts.
- Two axes of riskKnown CVEs plus supply-chain trust: abandoned, starjacking, typosquatting, single-maintainer and known malware.
- The recurring packagesUtility packages like
brace-expansionandbytesthat spread critical risk across unrelated components. - A dependency cascadeOne transitive memory-safety flaw (
bytesCVE-2026-25541) traced into a realistic vehicle data path. - Regulatory mappingFindings tied to R155, ISO/SAE 21434 and CRA deadlines — including the 24-hour reporting trap before SBOM.
- Full appendixPer-component data for all 43 components, reproducible from public sources.
Get the full benchmark report
Stop guessing whether a new CVE — or an abandoned package with no CVE — actually affects your code. This report shows which automotive open-source components are exposed on both axes, maps findings to compliance requirements, and traces a real dependency cascade. And it's free.
