The Eighth Edition: What the OWASP Top 10 Is and Is Not

▶ Watch (3:35)

The OWASP Top 10 is a data-driven awareness document for web application security, now in its eighth edition since 2003. The 2025 list draws on data from dozens of organizations, millions of records, and a community survey with hundreds of responses. It is not a standard, a checklist, or a compliance framework. The list covers the 10 most critical risk categories to give developers, security teams, and AppSec programs a concrete starting point. At the time of this talk, Release Candidate 1 had just gone live.

What Changed in the Rankings

▶ Watch (10:19)

Two structural changes stand out. SSRF merged into Broken Access Control because the data no longer supported it as a standalone entry. Broken Access Control stays at #1. Security Misconfiguration rose to #2. Injection held the top spot for 14 years, fell to #3 in 2021, and has dropped further in 2025. A 212-person industry survey on Software Supply Chain Failures found that 50% ranked it #1 in their top three picks, and every single respondent included it somewhere in their top three. That consensus locked it at #3.

Software Supply Chain Failures: From Controversial to #3

▶ Watch (22:51)

When the category first appeared in 2017 as “using components with known vulnerabilities,” roughly half of contributors argued it did not belong. By 2025 the term is industry standard. Real examples arrived fast. The Bybit crypto exchange lost $1.5 billion in February when an npm component, bundled in third-party software, activated only when Bybit’s hot wallet was used and performed normally the rest of the time. Phantom Raven, an npm worm from weeks before this talk, stole credentials and cryptographic keys and propagated by updating packages on infected systems. Prevention requires knowing exactly what your systems run, auditing CI/CD permissions quarterly, and training developers to vet third-party code before including it.

Mishandling Exceptional Conditions: A Brand New Entry at #10

▶ Watch (27:06)

This category covers code that fails to prevent, detect, or respond to unusual situations, leading to crashes and exploitable states. Attack paths include using error messages for reconnaissance, race conditions on partial transactions, replay attacks, and denial of service through uncapped resource consumption. Prevention starts with a global exception handler, failing closed on any incomplete transaction, rate-limiting everything, and centralizing input validation. Writing input validation eight different ways in one application is how three endpoints get injected while the rest stay clean.

Honorable Mentions and How to Apply the List

▶ Watch (31:14)

Three entries narrowly missed the top 10. Lack of application resilience, where an app cannot recover from unexpected failure, came closest. Memory mismanagement still occurs despite strong static analysis tooling. AI-assisted coding produces no CVEs of its own but generates vulnerable code resembling patterns from the 2003 list. Developers copying and pasting AI output without review reintroduce old bugs. The project team wants organizations to treat the list as a training and awareness starting point, not a compliance checklist to stop at once completed.

Q&A

Is Mishandling Exceptional Conditions a subset of Lack of Application Resilience? Both had enough data to stand separately, and addressing exception handling resolves most application resilience gaps as well. ▶ 36:50

Why did Insecure Design drop from #4 to #6? The data drove it down because automated tools rarely detect design flaws and organizations do not share incident reports that would prove its true frequency. ▶ 39:38

Are cryptographic failures and authentication failures the same category? Authentication addresses who a user is while cryptography protects data confidentiality and integrity; the CWE mappings in the document distinguish where each root cause belongs. ▶ 42:01

Notable Quotes

The bad news, prompt injection is number one in the OAS top 10 Neil Smithline · ▶ 16:48

50% exactly ranked this as number one. Neil Smithline · ▶ 23:45

I’ve had North Koreans in my system for nine months, Neil Smithline · ▶ 21:07

No one’s good enough to avoid it. Neil Smithline · ▶ 25:04

Key Takeaways

  • Software Supply Chain Failures earned #3 after the Bybit $1.5 billion loss and unanimous survey support.
  • Mishandling Exceptional Conditions is brand new at #10, covering uncaught errors that create exploitable application states.
  • Injection dropped from a 14-year reign at #1 as frameworks made it structurally harder to introduce.

About the Speaker(s)

Tanya Janca, known online as SheHacksPurple, is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She founded DevSec Station, a learning platform and community for software developers focused on secure coding, and contributes to the OWASP Top 10 project.

Neil Smithline has been an OWASP Top 10 Co-Leader since 2016, driving development of the standard through multiple release cycles. With 25 years in application security, he has built AppSec programs at companies ranging from startups to large enterprises, and served as the web lead for the 2025 edition.

Brian Glas has worked in IT for 25 years, with the last two decades in information and application security. He started as an enterprise Java developer, then built AppSec programs as both tech lead and manager. He is now Department Chair and Assistant Professor of Computer Science and Cybersecurity at Union University, where he founded the institution’s cybersecurity program.