> ## Content Index
> Fetch the complete content index at: https://itsfoss.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Red Hat's Lightwell Doesn't Wait for Upstream Maintainers to Act
- URL: https://itsfoss.com/news/red-hat-lightwell-status-update/
- Published: 2026-10-06T16:43:57.000Z
- Updated: 2026-10-06T16:43:57.000Z
- Description: A status update shows it clearing 400 vulnerabilities from Java libraries and a key service now being generally available.
- Author: Sourav Rudra
- Tags: News, Enterprise

[Lightwell](https://www.redhat.com/en/lightwell?ref=itsfoss.com) is Red Hat and IBM's response to a specific problem in enterprise open source security. Vulnerabilities sit in production library versions that upstream maintainers haven't patched and, in some cases, won't.

More than 90% of enterprise application code traces back to open source or third-party libraries, per figures [Red Hat cites](https://www.redhat.com/en/resources/closing-remediation-gap-lightwell-overview?ref=itsfoss.com), and a typical enterprise codebase **carries over 500 known vulnerabilities** at any given time.

They say that attacks on known vulnerabilities arrive, on average, a week before any patch exists.

Lightwell's approach is to bypass that timeline. Rather than waiting for upstream maintainers to push fixes to the library versions enterprises are actually running, **it backports those fixes directly**, delivering them through secure package repositories.

Red Hat reached out recently to share how far it has come.

## 400 down, more to come

To date, Lightwell has already managed to clear 400 previously unknown vulnerabilities across foundational Java libraries, going beyond reported [CVE](https://www.cve.org/?ref=itsfoss.com)s and contributing fixes upstream in line with responsible disclosure protocols.

The primary target so far has been organizations running Java environments with pinned dependency versions that can't be safely updated. Lightwell patches those in place, leaving the pinned version intact.

Coverage is also set **to expand beyond Java**, with *Python*, *JavaScript*, and *.NET* on the roadmap. Each will follow the same approach, with fixes backported to the versions already in production and applicable patches being contributed upstream.

## The Clearinghouse opens up

![a slide from red hat's technical demo for lightwell](https://itsfoss.com/content/images/2026/10/lightwell-technical-demo-slide.png)

Then there's *Clearinghouse Premier*, which has so far operated on restrictive terms. Before today, it was reserved for a pre-selected group of organizations in critical infrastructure sectors.

That restriction is now lifted, as it has reached *general availability*, which means any enterprise can sign up for Clearinghouse directly without waiting on an infrastructure designation to clear access.

You see, Lightwell runs across two access tiers. The **Lightwell Network**, which reached general availability in July as a self-service subscription open to any organization. It provides access to the backported patches and their compliance documentation.

What **Clearinghouse Premier** offers is more tailored. Organizations can specify which vulnerabilities matter most to their environment, get early notice before issues go public, and know exactly when fixes will arrive.

As a whole, Lightwell sits within IBM and Red Hat's [$5 billion commitment to open source security](https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era?ref=itsfoss.com), with both companies pointing to AI-assisted tooling raising the stakes on older, unpatched open source dependencies.

That stance is further strengthened by [Gunnar Hellekson](https://www.linkedin.com/in/gunnarhellekson?ref=itsfoss.com), Vice President and General Manager for Lightwell at Red Hat, who stated that:

> AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together.

If you are interested in what's being offered, a closer look before committing is possible via Red Hat's [technical demo](https://www.redhat.com/en/interactive-demo/lightwell-lightweight-technical-demo?ref=itsfoss.com), which will walk you through the patching workflow.