Security
mod_pagespeed 2.1 processes untrusted content — HTML, CSS, JavaScript, and images from origin servers. We take this seriously.
Reporting vulnerabilities
If you've found a security vulnerability, please email security@modpagespeed.com with details. Do not open a public GitHub issue for security vulnerabilities.
What to include
- • A description of the vulnerability and its potential impact.
- • Steps to reproduce the issue.
- • Affected versions, if known.
- • Your assessment of severity and impact.
Our commitment
We aim to acknowledge reports within a couple of business days (CET) and to triage shortly after. Critical vulnerabilities affecting production deployments jump the queue.
Safe harbor
We will not pursue legal action against security researchers who act in good faith. Good faith means: you report the vulnerability to us before disclosing publicly, you don't access or modify other users' data, and you don't degrade the service for others.
Scope
This security policy covers the mod_pagespeed 2.1 software (the module, the optimizer worker, and the cache layer) on Apache, nginx and IIS, and the modpagespeed.com website.
Security updates
Every security fix is listed on the release notes, with the release that carried it.
Evidence
Security disclosure
Report vulnerabilities to security@modpagespeed.com. GPG key on request. See security.txt.
CVE history
Tracked in the release notes.
Dependency audits
We aim to audit dependencies regularly, and we review them when a CVSS ≥ 7.0 CVE is disclosed against a direct dependency.
SBOM
We aim to publish an SBOM (CycloneDX format); it is on our roadmap. Enterprise customers can request a snapshot in the meantime via contact.
Architecture note
Both parts process untrusted content by design — they rewrite HTML, minify CSS and JavaScript, and transcode images from origins you configure. We take this attack surface seriously. Both parts of mod_pagespeed 2.1 build on a current toolchain and run with AddressSanitizer and UndefinedBehaviorSanitizer in CI, catching memory safety issues and undefined behavior before they reach production. The optimizer worker is written in C++23 with smart pointers and RAII throughout.
Threat model
mod_pagespeed processes untrusted images, CSS, JS, and HTML from origin servers. The worker process communicates only via a local Unix socket — it has no network access beyond the cache file and socket. All content parsing uses memory-safe patterns validated by continuous sanitizer testing (ASan, UBSan, TSan). No user data is transmitted externally.
Supply chain
All dependencies are pinned with SHA-256 checksums in the build configuration. Builds are reproducible from a given commit.