Application security, Risk Identification/Classification/Mitigation, Threat Management

OWASP Global AppSec conference: The new Top 10 list

WASHINGTON, D.C. — The Open Worldwide Application Security Project (OWASP) unveiled its Top 10 list of the current greatest threats to web applications at its Global AppSec conference here Thursday (Nov. 6).

It was the eighth edition of the Top 10 list since it was first compiled in 2003, and the first new edition since 2021. Two items from the 2021 list were merged into one, a third was redefined and retitled, eight stayed the same (although some dropped or rose in the rankings) and an entirely new threat — "Mishandling of Exceptional Conditions" — was added to the list.

"These items are finalized, but the writing around the list is still in draft," said Tanya Janca, one of five Top 10 list co-leaders and head of She Hacks Purple Consulting, Inc., in British Columbia. "We want your input and feedback."

Janca explained that the list is of the top risks to web apps, not a list of the Top 10 impacts, likelihoods or vulnerabilities. Nor should it be used as a standard or a checklist for compliance.

"The Top 10 list is a starting point, not an end goal," she added. "If you're building a security program, start here."

"This is a community-driven process," said Janca's co-leader, Neil Smithline, a fractional CISO based in New Hampshire, that draws on "millions of records, hundreds of survey respondents."

The other five co-leaders are Brian Glas, Department Chair of Computer Science at Union University in Tennessee, who was in the front row during the presentation and answered some questions; Andrew van der Stock, OWASP's Executive Director, based in Victoria, Australia; and Torsten Gigler, a security researcher based in Germany. Van der Stock and Gigler could not be present.

The final 2025 Top 10 list is as follows:

  1. Broken Access Control, holding the No. 1 slot from 2021 and incorporating the previous No. 10, Server Side Request Forgery
  2. Security Misconfiguration, moving up three slots
  3. Software Supply Chain Failures, redefined from 2021's No. 6, Vulnerable and Outdated Components
  4. Cryptographic Failures, dropping two slots
  5. Injection, dropping two slots
  6. Insecure Design, dropping two slots
  7. Authentication Failures, keeping the same rank
  8. Software or Data Integrity Failures, keeping the same rank
  9. Logging & Alerting Failures, keeping the same rank
  10. Mishandling of Exceptional Conditions, brand-new to the list

All around me are familiar faces

Janca and Smithline ran down what they called the "Familiar Eight," those eight risks that hadn't substantially changed from 2021.

No. 1, Broken Access Control, was hands-down the top selection among OWASP survey respondents, Janca said. She defined it as a failure in authorization that can be mitigated by thorough testing and a deny-by-default security policy.

No. 2, Security Misconfiguration, was a strong second and includes leaked credentials. It needs to be combated with regular hardening.

"Make it a process," Janca said.

No. 4, Cryptographic Failures, "used to be sensitive data exposure, but that's really the outcome," Janca explained. It's often caused by cryptographic misconfigurations and can be prevented by proper key management and stronger standards.

No. 5, Injection, is "when an attacker tricks you into running their code," Smithline said. "The good news is that this has dropped from No. 1 in 2017 to No. 3 in 2021 to No. 5 now. The bad news is that prompt injection is No. 1 in the Top 10 for LLM applications."

No. 6, Insecure Design, is often found only through manual testing but can be avoided by using threat modelling and secure design patterns.

"If you do a good job building junk, you end up with a good piece of junk," Smithline observed.

No. 7, Authentication Failures, "is when an attacker tricks you into thinking he's someone else," Smithline said. It includes credential stuffing and brute-force attacks and can be mitigated by proper password policies.

No. 8, Software or Data Integrity Failures, happens when systems mistakenly trust unverified data, critical components, infrastructure, or updates. This isn't quite the same as the new No. 3, Software Supply Chain Failures, because the corrupted inputs are accepted without being verified.

No. 9, Logging & Alerting Failures, simply leaves you in the dark due to lack of information. As the adage goes, you can't defend what you can't see.

"If you don't have good logging and alerting, you're not going to know," said Smithline. "I've had North Koreans in my systems for nine months and not known. It ended poorly."

A transition, an addition and three honorable mentions

Smithline then turned to the new No. 3, Software Supply Chain Failures, formerly "Vulnerable and Outdated Components" and before that, "Using Components with Known Vulnerabilities."

"We've changed the name twice," he said. "Everyone's aware of them now."

This one was top-ranked in the OWASP community survey, with 50% ranking it No. 1 and all respondents putting it in the top three. We're all familiar with recent devastating supply-chain attacks such as SolarWinds and Log4j, as well as the steady roar of malicious GitHub and NPM repository attacks.

The brand-new No. 10, Mishandling of Exceptional Conditions, is what happens when a program doesn't properly respond to unusual or unpredictable situations such as race conditions or replay attacks, Janca explained. 

One of three things happens: The application doesn't prevent an unusual situation from happening, it doesn't identify the unusual situation, or it doesn't response properly to the situation.

It can be prevented through catching and properly handling errors, implementing a global exception handler, watching for repeated errors, rate limiting, maintaining strict input validation and making sure systems fail closed.

Three other risks were deemed "honorable mentions" by just falling short of the Top 10: Lack of application resilience, when an app can't recover from a failure; memory mismanagement issues, such as buffer overflows; and AI assisted coding.

"Terrible code is being written," said Smithline. "We are concerned that people are copying and pasting, not reading or evaluating."

What to do, and how you can help

You can use the Top 10 list in your own organization by integrating it into your SDLC/AppSec programs, Janca said. But, she said, this list is meant to provide training and prioritization tips and raise awareness, not enforce compliance.

Smithline said that OWASP needs review, editing and translations of the release-candidate document.

"We're trying to get it finalized before Christmas," he said.

Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds