WSO2 Security and Compliance Documentation

Security and compliance resources for WSO2 products and cloud services, covering secure engineering practices, deployment hardening guidance, vulnerability management processes, and public security advisories.

Found a security issue? Report it privately through the appropriate WSO2 security reporting channel. See the vulnerability reporting guidelines for what to include.

Security Processes

Organizational security workflows, governance, incident handling, and vulnerability management practices.

Processes & Programs

Secure software development lifecycle, vulnerability management workflow, cloud security controls aligned with the CSA DevSecOps pillars, and the SaaS incident notification process.

Security Guidelines

Technical implementation guidance for secure engineering and hardened deployments.

Engineering & Operations

Secure coding standards, OWASP Top 10 prevention, security analysis tooling for WSO2 product teams, and hardening guidance for production deployments.

Security Announcements

Product advisories, CVE analysis, cloud security bulletins, and clarifications on industry incidents relevant to WSO2 products and customers.

Security Advisories

Public advisories for confirmed vulnerabilities in WSO2 products, including affected versions, CVSS severity, assigned CVE IDs, and the recommended fix or mitigation.

Third-Party CVE Analysis

Assessment of third-party CVEs flagged against WSO2 products, covering whether each CVE is exploitable in the WSO2 context, the reasoning, and any required customer action or mitigation.

Cloud Security Bulletins

Periodic bulletins for WSO2 cloud services (Asgardeo, Choreo, and the WSO2 API Platform) that summarize security events and changes within each reporting period.

Incident Clarifications

Analysis and clarifications for public security incidents and supply-chain events relevant to WSO2 products and services, covering the impact assessment and any required customer action.

Reporting

Channels for reporting vulnerabilities, abuse, and malicious content, alongside the researcher reward and acknowledgement program.

Report an Issue

Private mailing lists (with GPG keys) for reporting vulnerabilities in WSO2 products and infrastructure, and guidance on what to include in a report.

Reward & Acknowledgement

Eligibility criteria for the reward program and the Security Hall of Fame listing researchers acknowledged for past disclosures.