Anthropic’s OSS Scanner initiative has shown that vulnerability discovery in open-source software has become much faster than the ability of those who maintain these projects to verify and fix the issues. After six months of scanning widely used open-source projects, the company’s models identified more than 29,000 potential security vulnerability candidates, but only 516 vulnerabilities had been fixed upstream by October 2, 2026.
According to the initiative’s disclosure dashboard, six external security research companies reviewed 6,123 findings and confirmed 5,674 of them as valid. Anthropic sent a total of 6,157 findings to maintainers, resulting in the issuance of 584 CVE or GitHub Security Advisory identifiers, with some findings potentially receiving both identifiers. By contrast, about 23,000 candidates remained without human review.
A fast track that does not wait for full verification
To reduce the impact of the backlog, Anthropic made periodic free scans available to eligible projects using its most capable models, including Claude Mythos. Under this track, findings are sent directly to maintainers before the company verifies them, which Anthropic calls the “optional fast track.” The company sent nearly 5,000 unverified reports to projects that requested access to these findings.
Projects are built inside isolated virtual machines, and their internet connections are cut off during scanning. When possible, the reports also include a tool for reproducing the issue, an explanation of where it enters through bisection, and a proposed fix. The initiative’s GitHub repository does not contain the scanner itself, but rather the logging and setup tools.
Strong results, but not a final verdict
In an early test covering 97 high- or critical-severity findings across 48 projects, 85 findings passed the disclosure threshold. Eleven of the 12 remaining findings were real errors but duplicates of known issues or other findings, while only one finding was a false positive. However, this sample does not necessarily represent all 29,000 findings, nor does it clarify the tool’s performance on low-severity vulnerabilities or when run at scale.
Anthropic also acknowledged that maintainers reported overestimation of the severity of some findings, as well as cases in which the scanner misunderstood a project’s threat model. Therefore, not every candidate can be treated as a confirmed vulnerability before human review.
Why does this matter?
Statements from the OpenSSL, wolfSSL, PostgreSQL, and curl projects say that some reports were useful and could be verified quickly, while some included fixes that could be used almost as-is. But the gap between 5,674 confirmed findings and 516 fixes shows that the bottleneck does not always lie in finding the flaw. It also lies in testing it, backporting it to supported versions, assessing its impact on behavior that is compatible with users, and then releasing the fix.
Anthropic limits access to widely used, security-critical open-source projects under criteria similar to OSS-Fuzz, including verifying that the applicant is a core maintainer and that the project already tracks confirmed high- and critical-severity vulnerabilities. An unverified report does not trigger a 90-day disclosure deadline, while that period begins when Anthropic confirms the finding through its standard program. The company says it may later impose a deadline on some high-severity findings after giving projects an opportunity to opt out.
In practice, OSS Scanner offers a new capability for expanding the scope of security research, but it does not eliminate the human work required to turn findings into published fixes. Providing projects with free Claude Max 20x subscriptions through Claude for OSS may also help with analysis and coding, but it does not provide the time needed for review, testing, and maintenance.