Briefing

The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check

security
by Sponsored by HeroDevs · CVE-2026-22732

Run HeroDevs EOL scan to identify unpatched EOL dependencies in your stack.

What to do now

Run HeroDevs EOL scan on your SBOM to uncover hidden EOL vulnerabilities and patch or replace affected packages.

Summary

HeroDevs’ EOL DS tool reveals that most SCA scanners miss end‑of‑life (EOL) dependencies, leaving thousands of vulnerable packages unflagged.

The tool tracks over 12 million package versions across npm, PyPI, Maven, NuGet, Cargo, RubyGems, Go, Packagist, and crates.io, and finds that 5.4 million of those are EOL, a figure far larger than the ~7 000 versions reported by endoflife.date. Among the exposed packages, 81 000 EOL versions have known CVEs with no available fix path, and HeroDevs estimates the true number of vulnerable EOL packages could exceed 400 000.

The report cites Spring Security CVE‑2026‑22732 as a concrete example: the official CVE range lists Spring Security 5.7.x‑7.0.x, but the EOL 6.2.x version, used in Spring Boot 3.2, is also affected and was not flagged by scanners. HeroDevs has back‑ported a fix for its NES customers and confirmed that 80 % of CVEs disclosed on supported versions also affect uninvestigated EOL versions. The problem is compounded by the rapid growth of package releases—over 838 000 critical‑score releases on npm in 2025—and by AI‑driven vulnerability research that can uncover flaws in abandoned code without triggering official advisories.

The solution offered is a free EOL scan that can be run via CLI or by uploading an SBOM, which identifies both announced and abandoned packages across all major registries. Organizations should not treat scanner silence as safety; a clean scan simply indicates the package was not checked, not that it is secure.

Key changes

  • HeroDevs EOL DS tracks 12M+ package versions across npm, PyPI, Maven, NuGet, Cargo, RubyGems, Go, Packagist, and crates.io
  • 5.4M versions are EOL, far exceeding the ~7K reported by endoflife.date
  • 81K EOL versions have known CVEs with no fix path, and the true number may exceed 400K
  • Spring Security CVE‑2026‑22732 affects EOL 6.2.x used in Spring Boot 3.2, but scanners miss it
  • HeroDevs back‑ported a fix for NES customers
  • 80% of CVEs on supported versions also affect uninvestigated EOL versions
  • AI tools like Claude Mythos may uncover vulnerabilities in abandoned code without triggering advisories
  • HeroDevs offers a free EOL scan via CLI or SBOM upload

Affects

wp-customers enterprise e-com-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting