# Why end-of-life software means 400+ CVEs per year

DevFeed: [Why end-of-life software means 400+ CVEs per year](<https://devfeed.tech/articles/why-end-of-life-software-means-400-cves-per-year-13329.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-end-of-life-software-means-400-cves-per-year>)

Published: 2024-03-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [docker](<https://devfeed.tech/tags/docker.md>), [end-of-life](<https://devfeed.tech/tags/end-of-life.md>), [end-of-life-software](<https://devfeed.tech/tags/end-of-life-software.md>), [eol](<https://devfeed.tech/tags/eol.md>), [eol-software](<https://devfeed.tech/tags/eol-software.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article examines how vulnerabilities accumulate in end-of-life software and official EOL Docker images. Based on nearly 40 software projects, it reports an average accumulation of 218 CVEs every six months after end of life, with 98.4% occurring in image components, 1.4% in application dependencies, and 0.2% directly in the application.

## Source excerpt

Discover why End-of-Life software poses a high security risk with over 400 CVEs annually, emphasizing the importance of timely updates and secure practices.