
The Open Web Application Security Project (OWASP) has updated its essential list of the most critical web application security risks with its 2025 edition. This new list reflects how the threat landscape and software development practices have evolved. For security professionals, developers, and organizations, familiarizing themselves with this updated guidance is crucial to effectively prioritize security efforts.
What’s New in OWASP Top 10:2025?
The 2025 version introduces two new categories and consolidates one from previous editions, emphasizing a broader and systemic approach to risk beyond isolated vulnerabilities in code.
One of the major additions is the category of Software Supply Chain Failures. This category expands the previous “Vulnerable and Outdated Components” to encompass the entire software ecosystem, including dependencies, continuous integration and deployment (CI/CD) pipelines, build systems, and distribution infrastructure. Recent high-profile supply chain attacks have made it clear that securing the full software supply chain is now imperative to protecting web applications.
Another new entry is Mishandling of Exceptional Conditions, which focuses on how applications manage errors, failures, and unexpected states. Poorly handled exceptions can leak sensitive information, bypass security controls, or lead to denial of service, making error handling a critical security concern.
In addition, the Server-Side Request Forgery (SSRF) category from the 2021 list has been merged into the broader Broken Access Control category, which remains the number one risk, illustrating its enduring importance.
The Key Categories in the OWASP Top 10:2025
Broken Access Control continues to top the list. This covers vulnerabilities that allow attackers to bypass authorization mechanisms and access unauthorized resources or functionalities.
Security Misconfiguration has moved up in importance, highlighting risks from weak default settings, exposed services, unpatched systems, and inconsistent security configurations across environments.
The newly expanded Software Supply Chain Failures category stresses the need to detect and manage risks originating outside the application itself, reflecting modern development’s reliance on third-party and open source components.
Cryptographic Failures, which involve weak or incorrect cryptographic implementations, remain a significant risk but rank lower than in previous editions.
Classic risks like Injection flaws, including SQL, OS, and template injections, maintain their place as fundamental vulnerabilities developers must address.
Insecure Design emphasizes architectural and logic flaws arising from inadequate threat modeling and design processes.
Issues in Authentication and Session Management continue to be critical, involving weak login controls, poor session handling, and credential management.
Failures in Software or Data Integrity highlight the dangers of tampering or corruption of code or data, particularly in update operations and pipeline security.
Inadequate Logging and Alerting mechanisms impair an organization’s ability to detect and respond to attacks promptly.
Lastly, the newly added Mishandling of Exceptional Conditions addresses the security implications of poor error management and resilience in applications.
Why These Changes Matter
This update reflects a strategic shift in focus from isolated coding errors to broader system and lifecycle risks, including supply chain integrity and error resilience. These changes align with the reality that sophisticated attackers exploit not only code vulnerabilities but also weaknesses in processes, dependencies, and system design.
Practical Recommendations for Security Teams
- Prioritize securing the software supply chain by implementing strict controls and continuous monitoring of dependencies, build infrastructure, and deployment systems.
- Enhance application resilience by establishing secure and consistent error handling mechanisms that do not leak information or allow service disruptions.
- Continue to enforce robust access control policies and regularly audit configurations to prevent unauthorized access and misconfigurations.
- Integrate security early in the software development lifecycle through threat modeling, secure design practices, and continuous testing.
- Maintain comprehensive logging and alerting to detect suspicious activities and respond swiftly.
The OWASP Top 10:2025 offers a data-driven and community-vetted roadmap to help organizations focus their security resources on the most impactful risks in modern web applications. Aligning security strategies with these priorities is essential for building resilient and secure software in today’s complex threat landscape.



