Skip to content

Security: Pastalikek65/edgewasm-runtime

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
main ✅ (active development)
< 0.1.0 ❌

EdgeWasm-Runtime is pre-1.0. Security fixes land on main; there are no maintenance branches yet.

Threat model

This runtime executes untrusted WASM modules and can be deployed to the public internet. The security boundary is documented in docs/OPERATIONS.md §Security and docs/ARCHITECTURE.md §12. In short:

  • Untrusted code runs inside wasmtime's sandbox with hard memory/table/time caps; no host filesystem or network access by default.
  • unsafe is forbidden workspace-wide (one audited AOT-deserialization site relaxes to deny).
  • The gateway itself is the second boundary: API-key auth, per-key rate limiting, bounded bodies, and concurrency backpressure.
  • Robustness fuzzing (tests/fuzz.rs, wasm-smith) feeds the sandbox random modules on every CI run.

Things deliberately out of scope (documented): TLS termination (the edge's job — Ingress/load balancer), and distributed rate limiting's Redis dependency (fail-closed by design).

Reporting a vulnerability

Do not open a public issue for security problems. Report privately to the repository maintainers via GitHub's private vulnerability reporting (Repository → Settings → Security → Report a vulnerability), or open a security advisory.

Please include:

  • The affected version/commit.
  • A minimal repro (WAT/WASM module or HTTP request sequence).
  • Impact and, if known, a suggested fix.

You should receive a response within 5 business days. We will keep you informed of progress and credit you (with your consent) in the fix.

Process

  1. Triage and confirm the report.
  2. Fix on main with a regression test that fails before the fix.
  3. Coordinate disclosure timing with the reporter; publish an advisory when warranted.

There aren't any published security advisories