Security Policy
Overview
This document covers the UVHTTP security policy: dependency management, vulnerability response, and security practices.
Dependency Management
Current Dependencies
| Dependency | Version (in .gitmodules) | Purpose | Update Policy |
|---|---|---|---|
| libuv | git submodule | Event loop | Regular updates |
| mbedtls | git submodule | TLS/SSL | Security updates priority |
| mimalloc | git submodule | Memory allocator | Regular updates |
| cjson | git submodule | JSON parsing | Regular updates |
| llhttp | git submodule | HTTP parsing | Regular updates |
| uthash | git submodule | Hash table | Regular updates |
| xxhash | git submodule | Fast hashing | Regular updates |
| googletest | git submodule | Testing framework | As needed |
Dependency Update Policy
1. Security Updates (High Priority)
- Trigger: CVE vulnerability or serious security issue discovered
- Response Time: 7 days for assessment, 14 days for fix
- Process:
- Assess vulnerability impact scope
- Check upstream fix version
- Update dependency version
- Run full test suite
- Release security patch version
2. Feature Updates (Medium Priority)
- Trigger: New features, performance improvements, API changes
- Response Time: Quarterly assessment
- Process:
- Evaluate new feature value
- Check API compatibility
- Update dependency version
- Update related documentation
- Release minor version
3. Maintenance Updates (Low Priority)
- Trigger: Dependency version outdated (> 1 year)
- Response Time: Semi-annual assessment
- Process:
- Check compatibility
- Update dependency version
- Run tests
- Release patch version
Dependency Version Pinning
All dependency versions are pinned in .gitmodules to ensure reproducible builds.
Advantages:
- Reproducible builds
- Avoid unexpected breaking changes
- Easier issue tracking
Disadvantages:
- Manual dependency updates required
- May miss security updates
Mitigation:
- Regular security scanning
- Subscribe to security advisories
- Establish automated checks
Security Audits
Regular Audit Schedule
| Audit Type | Frequency | Owner |
|---|---|---|
| Dependency vulnerability scan | Weekly | Automated |
| Code security review | Monthly | Security team |
| Penetration testing | Quarterly | Third-party |
| Architecture security review | Semi-annually | Security team |
Automated Security Scanning
Use the following tools for automated security scanning:
Dependency Scanning
bash# Use GitHub Dependabot # Configuration file: .github/dependabot.ymlStatic Code Analysis
bash# Use cppcheck cppcheck --enable=all src/Memory Safety Checks
bash# Use Valgrind valgrind --leak-check=full --show-leak-kinds=all ./uvhttp_serverAddressSanitizer (leaks, use-after-free, overflows)
bashcmake -B build_asan -DCMAKE_BUILD_TYPE=Debug -DENABLE_ASAN=ON .. cmake --build build_asan -j$(nproc) (cd build_asan && ctest --output-on-failure) # full suite, leak detection onUndefinedBehaviorSanitizer (signed overflow, shifts, alignment, ...)
bashcmake -B build_ubsan -DCMAKE_BUILD_TYPE=Debug -DENABLE_UBSAN=ON .. cmake --build build_ubsan -j$(nproc) (cd build_ubsan && ctest --output-on-failure)ASan and UBSan cannot be combined in a single build; run them as separate builds.
Security Best Practices
Input Validation
UVHTTP validates input:
URL Validation
- Maximum URL length: 2048 bytes
- Path traversal protection
- URL encoding validation
Header Validation
- Maximum header count: 64
- Maximum header name length: 256 bytes
- Maximum header value length: 4096 bytes
Body Size Limits
- Maximum body size: 10MB (configurable)
- Chunked transfer encoding support
Buffer Overflow Protection
All string operations use safe functions:
// Safe string copy
if (uvhttp_safe_strcpy(dest, sizeof(dest), src) != 0) {
return UVHTTP_ERROR_INVALID_PARAM;
}
// Safe string length
size_t len = strlen(src);
if (len >= sizeof(dest)) {
len = sizeof(dest) - 1;
}
strncpy(dest, src, len);
dest[len] = '\0';TLS Configuration
Recommended TLS configuration:
// Enable TLS 1.3 only
mbedtls_ssl_conf_min_tls_version(&conf, MBEDTLS_SSL_TLS_1_3);
// Enable certificate verification
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_REQUIRED);
// Set secure cipher suites
const int ciphers[] = {
MBEDTLS_TLS_AES_256_GCM_SHA384,
MBEDTLS_TLS_CHACHA20_POLY1305_SHA256,
0
};
mbedtls_ssl_conf_ciphersuites(&conf, ciphers);DoS Protection
UVHTTP applies several DoS protections:
Rate Limiting
- Token bucket algorithm
- Configurable limits per IP
- Whitelist support
Connection Limits
- Maximum connections: 2048 (configurable)
- Connection timeout: 60 seconds
- Request timeout: 30 seconds
Resource Limits
- Maximum body size: 10MB
- Maximum header size: 8KB
- Maximum concurrent requests per connection: 100
Vulnerability Reporting
Reporting Process
If you discover a security vulnerability, please report it responsibly:
- Do not create a public issue
- Send email to: security@uvhttp.org
- Include: Vulnerability description, reproduction steps, affected versions
- Response Time: We will respond within 48 hours
Vulnerability Handling Process
Acknowledgment (within 48 hours)
- Confirm receipt of report
- Assign severity level
- Estimate fix timeline
Assessment (within 7 days)
- Reproduce vulnerability
- Assess impact
- Develop fix
Fix Development (within 14 days)
- Implement fix
- Write tests
- Review code
Release (within 21 days)
- Prepare security advisory
- Release patch version
- Coordinate disclosure
Severity Levels
| Severity | Description | Response Time |
|---|---|---|
| Critical | Remote code execution | 48 hours |
| High | Data leakage or DoS | 7 days |
| Medium | Information disclosure | 14 days |
| Low | Minor security issue | 30 days |
Security Features
Memory Safety
- Sanitizer-verified: The full 91-test suite passes clean under AddressSanitizer (with leak detection — zero leaks, zero use-after-free, zero buffer overflows) and UndefinedBehaviorSanitizer (zero undefined behavior). See
.github/workflows/ci-nightly.yml(test-memory+test-ubsanjobs). - Zero compilation warnings: All code compiles with
-Werror - Memory allocator: mimalloc for improved memory safety (optional; system allocator also supported)
- Buffer overflow protection: all string operations validated
- Memory leak detection: regular Valgrind and AddressSanitizer testing
Input Validation
- URL validation: Length limits, path traversal protection
- Header validation: Size limits, format validation
- Body validation: Size limits, encoding validation
- Parameter validation: Type checking, range validation
Secure Defaults
- TLS 1.2/1.3: both enabled by default, TLS 1.3 as maximum
- Certificate verification: Required by default
- Secure cipher suites: Pre-configured
- Rate limiting: Enabled by default
Security Checklist
Before deploying to production, ensure:
- [ ] All dependencies are up to date
- [ ] No known vulnerabilities in dependencies
- [ ] TLS is properly configured
- [ ] Rate limiting is enabled
- [ ] Input validation is comprehensive
- [ ] Error messages don't leak sensitive information
- [ ] Logging doesn't expose sensitive data
- [ ] File permissions are correct
- [ ] Firewall rules are configured
- [ ] Monitoring and alerting are set up
Security Resources
- Security Advisories: https://github.com/adam-ikari/uvhttp/security/advisories
- CVE Database: https://cve.mitre.org/
- OWASP Top 10: https://owasp.org/www-project-top-ten/
- Security Best Practices: https://wiki.sei.cmu.edu/confluence/display/seccode/Top+10+CERT+C+Coding+Rules (requires login)
- Alternative: https://www.cert.org/confluence/display/seccode/Top+10+CERT+C+Coding+Rules
Contact
For security-related questions or to report vulnerabilities:
- Email: security@uvhttp.org
- GitHub Security: https://github.com/adam-ikari/uvhttp/security
- PGP Key: Available on request
Last Updated: 2026-02-02
Version: 1.0
Maintainer: UVHTTP Security Team