Triad ICS
Menu

Insights/Technical Deep-Dives

OWASP Top 10:2025 — What’s New and What Indian Developers Must Test First

Published

Reading time2 minutes

FromTriad ICS Research

Supply chain failures and exception handling enter the list. SSRF folds into access control. Here is what changes for your test plan.

The final OWASP Top 10:2025 is out, and it is the first update since 2021. The list is built from contributed application testing data and a community survey, and it remains the most widely used baseline for web application security testing, including in the VAPT engagements we run.

The 2025 list

  • A01:2025 Broken Access Control
  • A02:2025 Security Misconfiguration
  • A03:2025 Software Supply Chain Failures
  • A04:2025 Cryptographic Failures
  • A05:2025 Injection
  • A06:2025 Insecure Design
  • A07:2025 Authentication Failures
  • A08:2025 Software or Data Integrity Failures
  • A09:2025 Security Logging and Alerting Failures
  • A10:2025 Mishandling of Exceptional Conditions

What changed

Broken Access Control stays at number one, and Server-Side Request Forgery, a separate category in 2021, is now folded into it. Security Misconfiguration rises to number two, reflecting how much of modern application behaviour is set by configuration rather than code.

Two categories are new. Software Supply Chain Failures (A03) expands the old “vulnerable and outdated components” idea to the whole chain: dependencies, build systems, CI/CD pipelines and distribution. Mishandling of Exceptional Conditions (A10) covers errors that are handled badly, such as failing open, leaking details in error messages or leaving systems in an inconsistent state.

What Indian development teams should test first

  • Access control on every API: can user A read or modify user B’s order, invoice or KYC document by changing an ID? This remains the most common serious finding in Indian fintech and e-commerce applications.
  • Configuration of cloud and frameworks: debug modes, default credentials, verbose errors and permissive CORS in production.
  • Your dependency and build chain: lock files, pinned versions, a software bill of materials, and who can push to the pipeline.
  • Error paths: what does your payment callback do when the gateway times out? Does a failed validation grant access by default?
  • Logging that someone actually reviews, so that you can meet CERT-In’s six-hour reporting expectation.

Using the list well

The Top 10 is an awareness document, not a complete testing standard. For deeper assurance, pair it with the OWASP Application Security Verification Standard (ASVS) and test for business-logic flaws that no generic list can capture.

This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.

Turn Insight into Action