IBM and Red Hat report hundreds of open source fixes with Lightwell Clearinghouse scheme

IBM and Red Hat have fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through their Lightwell Clearinghouse initiative.

Announced earlier this year with a $5 billion investment and more than 20,000 engineers, Lightwell Clearinghouse lets enterprise customers submit open source software dependencies for priority review and fixes.

"For over two decades, Red Hat has backported security patches across thousands of packages," said Matt Hicks, president and CEO of Red Hat.

"Lightwell scales this exact model across a wider scope of open source ecosystems. We are applying the same discipline, upstream commitment, and engineering rigor across all active application layers."

Since the initial Lightwell launch, the duo said they have uncovered, remediated, and backported fixes for hundreds of previously unknown bugs in widely deployed, production-grade software.

"Finding and neutralizing 400-plus novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started," said Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat.

Lightwell is designed to make the most of the two firms' open source engineering expertise, together with Red Hat’s secure software supply chain capabilities, build infrastructure and open source community relationships.

Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.

The project uses AI-assisted engineering workflows, although AI-generated patches aren't automatically distributed to customers but are first tested and validated by humans.

It develops version-specific fixes for open source application dependencies in production systems that are delivered through secured repositories that connect with customers’ existing IT processes.

This, the two firms said, allows organizations to address difficult or previously unknown vulnerabilities without needing to replace their current security scanners, software repositories, development pipelines or testing processes.

Through Lightwell Network, IT teams can access verified patches, bring remediated software into their existing workflows and establish an ongoing process for addressing vulnerabilities.

Broader open source gains

The fixes that are developed through Lightwell are contributed to upstream open source projects under responsible disclosure protocols, said the firms, maintaining embargo protections for Lightwell Clearinghouse participants.

Lightwell Network launched commercially in July, with more than 6,500 patched and digitally signed software dependencies for Java, Python, and other languages. Universities, non-governmental organizations and think tanks were given free access in August, and it's now been made generally available.

"AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together," said Hellekson.

"Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime."

FOLLOW US ON SOCIAL MEDIA

You can also .

Original source IBM and Red Hat report hundreds of open source fixes with Lightwell Clearinghouse scheme

Back to home