pchickey opened PR #14408 from pchickey:fix_ghsa_c9gc_main to bytecodealliance:main:
Fixes https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-c9gc-w9vx-w86p
wasmtime-wasi-httpdoes not enforce the write allowance thatwasi:io/streams.check-writereturns for WASIp2 outgoing HTTP bodies.A guest can call
check-write, get the default configuredDEFAULT_OUTGOING_BODY_CHUNK_SIZEof 1M (or whatever value the chunk size has been customized to in an embedder's ownWasiHttpHooksimpl), and then hand a much larger buffer towrite. Thewritecall will succeed for sizes larger than permitted bycheck-write, disobeying the spec'swasi:io/streams,writeprecondition which says such awritemust trap. Due to this behavior, eachoutgoing-bodyresource created by the guest (trivial by way of creating anoutgoing-requestoroutgoing-response) can be used to hold a host allocation of at least one linear memory sized vector for the lifetime of the guest's store.This PR adds the check that a call to
writethat the passed list of bytes does not exceed the size permitted bycheck-write, and traps if it does. This new behavior is checked with a regression test.
pchickey requested dicej for a review on PR #14408.
pchickey requested wasmtime-wasi-reviewers for a review on PR #14408.
pchickey requested wasmtime-core-reviewers for a review on PR #14408.
:thumbs_up: dicej submitted PR review.
pchickey added PR #14408 wasmtime-wasi-http: enforce check-write budget on outgoing bodies to the merge queue.
:check: pchickey merged PR #14408.
pchickey removed PR #14408 wasmtime-wasi-http: enforce check-write budget on outgoing bodies from the merge queue.
Last updated: Oct 11 2026 at 04:10 UTC