Aug 20266 min read
FRAMEWORKS

What the OWASP Top 10:2025 changed, and what it means for the application you already have

The new edition keeps broken access control at number one, folds SSRF into it, and adds two categories that say a lot about where attacks are coming from now.

The OWASP Top 10 is not a standard and was never meant to be one. It is an awareness document — a ranked list of the most important categories of web application risk, built from data contributed by testing firms and a community survey. But because nearly every customer questionnaire asks about it, it matters what it says.

What stayed the same

Broken access control is still number one, and server-side request forgery, which had its own entry in 2021, is now part of it. That is the right call: SSRF is fundamentally a server doing something on behalf of a user that the user should not be able to make it do.

Security misconfiguration rose to second place, which matches what we see. Modern applications are assembled from cloud services, each with its own settings, and the defaults are rarely the secure option.

What is new

Two additions stand out. Software supply chain failures broadens the old “vulnerable and outdated components” category to the whole chain — dependencies, build systems, package registries and the scripts your pages load from third parties. And mishandling of exceptional conditions covers what happens when things go wrong: errors that leak internals, failures that fail open, and states the developers never expected.

“The list moved from the code you wrote to everything your code depends on, and everything that happens when it breaks.”

What it means for an existing application

If your last test was mapped to the 2021 list, nothing about your application changed when the new edition was published. But the questions you will be asked did. Expect questionnaires to ask how you manage dependencies and third-party scripts, and how your application behaves under error conditions.

Practically, three things are worth doing now: generate and keep a software bill of materials for each application, inventory the third-party scripts on your most sensitive pages, and review how your error handling behaves — especially whether any authorisation check can be skipped when something upstream fails.

Use it as a floor, not a scope

The Top 10 is a good list of things that must be covered and a poor definition of a complete test. For that, OWASP’s Application Security Verification Standard — ASVS 5.0, released in 2025 — sets out testable requirements at three levels. A report that says “verified against ASVS Level 2” tells a reader far more than one that says “tested for the OWASP Top 10”.

TL;DR

The short version

It is an awareness list, not a standard

It ranks categories of risk. It does not define a complete test.

Access control is still first

Broken access control stays at number one, now including SSRF.

Misconfiguration moved up

Cloud-assembled applications inherit a lot of settings, and defaults are rarely secure.

Supply chain is now its own category

Dependencies, build pipelines and third-party scripts are all in scope.

Errors are a security question

Mishandling exceptional conditions covers leaks and checks that fail open.

Verify against ASVS 5.0

For a defined, repeatable scope, cite ASVS levels rather than the Top 10 alone.

Written by

The Penspy team

Testers and auditors · Penspy Cyber Security

Written by the people who do the testing and the audits, from what we actually find in the work. No vendor sponsorship, no product to sell you at the end.

Send us a note