Time-to-Patch Analysis

How fast do AI/ML packages respond to security vulnerabilities? Benchmarking 78 packages with 3+ known CVEs.

Based on NVD publication-to-modification data. Updated continuously.

78
Packages Analyzed
69.0d
Industry Average
0.0d
Fastest (Gemini CLI)
1372.0d
Slowest (TensorFlow)
CISO Analysis Data updated 2026-09-14

Executive Summary

The AI/ML ecosystem still has a patch-rate gap, but the picture is sharper than the early "crisis" narrative suggested. Across all CVE-to-package associations we track, 42.8% have a documented fix available (1,640 of 3,831 entries) — better than first feared, but well below the 60-70% rate typical of mainstream software. For CISOs managing AI deployments, this means patch management remains a strategic risk decision: when no vendor-supplied fix exists at the moment of disclosure, you cannot simply "patch and move on."

The packages topping the risk-score table are: torch (85/100), ollama (84), mlflow (81), gradio (80), litellm (79). These combine high CVE volume, critical severity, and in many cases active exploitation. They are not niche tools; they are foundational components of enterprise AI stacks.

Key Findings

  • 42.8% global patch coverage across 3,831 CVE-package associations. The remaining 1,640 associations have no documented fix in package metadata at the time of analysis.
  • torch remains #1 by risk score (85/100) — 47 CVEs, ~14% patch coverage. High blast radius through downstream dependents amplifies every vulnerability.
  • ollama (84/100) is the highest-risk inference platform with 35 CVEs including SSRF, authentication bypass, and command injection. Patch coverage at ~20% — release cadence outpaces backport discipline.
  • mlflow (81/100) has 83 CVEs making it the most vulnerability-dense MLOps platform. ~36% patch coverage. Path traversal, authentication bypass, and code execution dominate, particularly concerning given its role in model training pipelines.
  • gradio (80/100) and litellm (79/100) patch faster than peers. ~29% and ~55% of their CVE-products have a recorded fix respectively, meaningfully better than ollama or torch despite similar disclosure volume.
  • TensorFlow has the highest absolute CVE count (438) but a lower risk score (67/100) thanks to Google's relatively mature security process and faster patch cadence than newer frameworks.
  • Newer agent platforms still trail. Flowise, LangFlow, and similar tools continue to show patch coverage in the low double digits while their feature surface grows monthly.

Trend Analysis

The patch-velocity data reveals a fundamental tension in the AI ecosystem: speed of innovation versus security maturity. Established projects (TensorFlow, scikit-learn) maintain better patch coverage because they have dedicated security teams, established CVE processes, and corporate or community backing. The newer wave of LLM frameworks, agent platforms, and inference servers grow user bases faster than their security posture can keep pace.

The "move fast and break things" culture that drove web development's early years is repeating in AI tooling, with higher stakes. An unpatched RCE in a web framework affects a website. An unpatched RCE in an inference server affects every model it serves and every system it connects to.

OpenSSF Scorecard scores correlate moderately with patch velocity: packages scoring above 7/10 patch noticeably faster than those below 4/10. Branch protection, dependency updates, and a published security policy are reliable predictors of patch responsiveness — and they are visible to anyone evaluating a dependency before adopting it.

Recommendations

  1. Evaluate AI dependencies by patch velocity, not just functionality. When choosing between competing AI frameworks, include time-to-patch and patch coverage as selection criteria. A tool that patches in 7 days is categorically safer than one that takes 90 days, regardless of feature parity.
  2. Implement compensating controls for unpatched AI vulnerabilities. With ~42.8% patch coverage, you cannot rely on vendor patches alone. Deploy WAF rules, network segmentation, input validation, and runtime monitoring as compensating controls.
  3. Prioritize patching for the top-5 risk-score packages. If your stack includes torch, ollama, mlflow, gradio, or litellm, treat their CVEs as high-priority patch cycles — these combine high severity, active exploitation, and wide blast radius.
  4. Monitor OpenSSF Scorecards for your AI dependencies. Packages with scores below 4/10 are statistically more likely to have slow or missing patch cycles. Treat that as a red flag in procurement decisions.
  5. Budget for AI-specific vulnerability management. The patch gap means your team will spend disproportionate time on workarounds, compensating controls, and risk acceptances for AI components. Plan staffing and tooling accordingly.

Methodology

Time-to-patch metrics are derived from `cve_products.first_patched_version` — the earliest fixed version recorded against a CVE for a given package. Patch coverage is the share of CVE-product associations with a non-null patched version. Risk scores combine 7+ signals: CVE volume, severity distribution, EPSS exploitation probability, KEV status, blast radius (downstream dependents), OpenSSF scorecard, and patch responsiveness. Data sources include NVD, GitHub Security Advisories, PyPI, npm, OSV, and vendor changelogs. All numeric values in this analysis are pulled live from the database on every page load.

# Package CVEs Patched Patch Rate Avg Days
1 Gemini CLI 4 1 25% 0.0d
2 Tokenizers 4 3 75% 0.0d
3 LlamaIndex 7 1 14% 0.0d
4 H2O 25 2 8% 0.1d
5 Llama Stack 3 2 67% 0.3d
6 Local Deep Research 3 3 100% 0.3d
7 Composio 4 1 25% 1.5d
8 Flowise 199 97 49% 1.8d
9 Anthropic Node 3 2 67% 2.9d
10 MCP Atlassian 39 33 85% 3.9d
11 OpenClaw 559 201 36% 4.1d
12 DeepSeek TUI 29 29 100% 4.7d
13 n8n 240 126 53% 5.1d
14 Claude Code 44 30 68% 5.2d
15 Open WebUI 176 146 83% 5.3d
16 Fickling 16 14 88% 5.4d
17 PraisonAI Agents 70 41 59% 6.2d
18 smolagents 8 2 25% 9.7d
19 MLX 4 2 50% 10.9d
20 picklescan 112 59 53% 11.8d
21 PraisonAI 175 114 65% 12.5d
22 LangGraph 19 16 84% 12.5d
23 pgvector 3 2 67% 12.9d
24 Anthropic Python 51 46 90% 13.4d
25 Cohere 8 1 13% 13.8d
26 BentoML 21 11 52% 14.1d
27 Langroid 11 11 100% 14.4d
28 Panel 79 54 68% 14.7d
29 Cline 7 5 71% 15.6d
30 DeepSeek TUI 13 4 31% 16.6d
31 LMDeploy 10 6 60% 18.0d
32 MCP Server K8s 4 3 75% 20.1d
33 Streamlit 14 2 14% 20.7d
34 HF Datasets 14 13 93% 22.5d
35 OpenAI Python 7 1 14% 23.0d
36 Microsoft APM 14 9 64% 23.3d
37 LoLLMs 12 4 33% 23.5d
38 MONAI 8 8 100% 23.6d
39 Ollama 35 7 20% 25.9d
40 skops 3 3 100% 26.4d
41 Jupyter 71 43 61% 30.2d
42 XGrammar 5 4 80% 39.8d
43 Milvus 3 1 33% 41.2d
44 LangChain Core 9 7 78% 43.5d
45 ONNX 16 13 81% 44.7d
46 LiteLLM 44 24 55% 46.1d
47 vLLM 257 67 26% 46.8d
48 LangChain Community 8 4 50% 47.6d
49 Keras 29 18 62% 48.1d
50 LlamaIndex Core 7 7 100% 49.7d
51 Chainlit 8 5 63% 53.9d
52 Diffusers 4 3 75% 56.5d
53 ExecuTorch 13 12 92% 64.1d
54 SageMaker 7 6 86% 71.4d
55 Langflow 181 30 17% 73.3d
56 MLflow 95 34 36% 74.5d
57 LlamaIndex 16 14 88% 81.3d
58 MS Swift 5 1 20% 84.2d
59 Transformers 56 24 43% 87.5d
60 Jupyter Notebook 62 53 86% 89.9d
61 InvokeAI 6 3 50% 91.6d
62 Gradio 83 24 29% 104.2d
63 Ray 19 13 68% 148.3d
64 LLaMA Factory 4 3 75% 166.5d
65 LangChain 78 22 28% 178.5d
66 OpenAI Node 30 15 50% 185.3d
67 Pydantic AI 12 11 92% 189.0d
68 PyTorch 57 8 14% 223.9d
69 Label Studio 10 5 50% 274.9d
70 PyTorch Lightning 9 5 56% 345.5d
71 TensorFlow 470 20 4% 1372.0d
72 ChromaDB 6 0 0% -
73 Mistral AI 12 0 0% -
74 ChuanhuChatGPT 4 0 0% -
75 WPBot 15 0 0% -
76 scikit-learn 3 0 0% -
77 GPT Academic 6 0 0% -
78 LLaMA Factory 6 0 0% -

Monitor your stack's patch velocity

Get real-time alerts when CVEs in your AI stack get patched. Track patch rates and response times for the packages you depend on.

Start Monitoring