Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
OWASP® Foundation

OWASP® Foundation Vendor Cyber Rating & Cyber Score

owasp.org

The Open Worldwide Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of software. Our mission is to make application security "visible,"​ so that people and organizations can make informed decisions about application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work.


OWASP® Foundation A.I CyberSecurity Scoring

OWASP® Foundation
Company Information
Website:https://http://owasp.org
Employees number:648
Number of followers:288,043
NAICS:5112
Industry Type:Software Development
Homepage:owasp.org
OWASP® Foundation Risk Score (AI oriented)
Between 750 and 799
logo
OWASP® FoundationSoftware Development
Updated:
30/03/2026
760/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
OWASP® Foundation Global Score (TPRM)
xxxx
logo
OWASP® FoundationSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OWASP® Foundation
OWASP® FoundationFair
Current Score
760Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
761Before Incident
MAY 2026
761Before Incident
APRIL 2026
760Before Incident
MARCH 2026
760Before Incident
FEBRUARY 2026
760Before Incident
JANUARY 2026
762Before Incident
Vulnerability
28 Jan 2026OWASP® Foundation
OWASP ZAP: ZAP Releases Hotfix After JS Engine Leak Disrupts Active Scanning

Memory Leak in JavaScript Engine Affecting Active Scans in OWASP ZAP

760After Incident
LOW-2
OWA1769633044
ZAP Project Identifies Memory Leak in JavaScript Engine Affecting Active Scans The OWASP ZAP project has uncovered a memory leak in its embedded JavaScript engine, which maintainers believe has existed for some time but became more widespread following a recent update. The issue surfaced after the introduction of a new JavaScript-based scan rule in the OpenAPI add-on, which increased the frequency and consistency of JavaScript evaluations during active scans. The vulnerability primarily impacts users running active scans, as the OpenAPI rule triggers repeated JavaScript execution, leading to steadily rising heap usage within the ZAP process. Over time, this can degrade scanner performance, stall scan progress, or cause the JVM to terminate due to memory exhaustion. Users may notice escalating RAM consumption, increased garbage-collection activity, and failures resembling resource exhaustion rather than a single crash. ZAP maintainers have released a hotfix to address the leak, prioritizing stability for active scans. Until the fix is applied, users can mitigate the issue by updating ZAP and its add-ons, disabling the problematic JavaScript scan rule or the OpenAPI add-on, increasing the JVM heap size (as a temporary measure), or splitting large OpenAPI definitions into smaller scan scopes. Passive scanning remains largely unaffected. The affected component is the core JavaScript engine, with the OpenAPI add-on’s new scan rule identified as the trigger. The impact is classified as a resource exhaustion issue leading to a local denial-of-service condition. The recommended remediation is to update all components via the ZAP Marketplace.
INCIDENT DETAILS -
TYPE
Resource Exhaustion
IMPACT
Systems Affected: OWASP ZAP active scan functionalityDowntime: Possible scan stalls or JVM terminationOperational Impact: Degraded scanner performance, increased garbage-collection activity
DECEMBER 2025
762Before Incident
NOVEMBER 2025
762Before Incident
OCTOBER 2025
762Before Incident
SEPTEMBER 2025
762Before Incident
AUGUST 2025
762Before Incident
JULY 2025
762Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for OWASP® Foundation ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in May 2026 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in April 2026 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in March 2026 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in February 2026 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in January 2026 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in December 2025 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in November 2025 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in October 2025 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in September 2025 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in August 2025 ?
?
What was OWASP® Foundation's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on OWASP® Foundation's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with OWASP® Foundation ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view OWASP® Foundation's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?