Global open-source solutions company Red Hat and IBM said on Tuesday they found and fixed more than 400 previously unknown vulnerabilities in Java libraries through Lightwell, a security infrastructure they provide as part of efforts to deliver safer open-source software.
They carried out backporting so the fixes can be applied to earlier versions as well.
Red Hat said this shows that even codebases that have been used stably for a long time require continuous management as threat environments change.
Red Hat and IBM also launched Lightwell Clearinghouse, which allows enterprise customers to request priority reviews and vulnerability fixes for specific open-source software dependencies.
According to Red Hat, Lightwell supports the development of version-specific fixes for open-source applications in production systems through Red Hat and IBM open-source engineering expertise, Red Hat's open-source community network, advanced AI-based engineering workflows, and Red Hat software supply chain capabilities and build infrastructure.
The fixes are provided through a security repository linked to customers' existing IT processes. Red Hat said this allows companies to respond to hard-to-resolve or previously unknown vulnerabilities without replacing the security scanners and software repositories, development pipelines and testing processes they currently use.
Red Hat said it provides applicable fixes developed through Lightwell back to upstream open-source projects under the principle of responsible disclosure.
Gunnar Hellekson (거너 헬렉슨), vice president and general manager of Lightwell at Red Hat, said, "The threat environment has changed in an instant with the emergence of AI agents. AI agents exploit old software vulnerabilities at mechanical speed. It does not matter whether a codebase is 10 years old or assessed as stable. That is because if there is even a small gap, multiple vulnerabilities can be linked and developed into an attack. Finding a bug is only half of solving the problem. What is important is to backport fixes directly into production applications that are currently in operation, so customers do not have to choose between security and keeping services running. Discovering and neutralising more than 400 new vulnerabilities in a short time shows how quickly Lightwell can respond."