Bug description
Findings are all related to the Margo (pre-draft) specification, not to any implementation / executable code. Therefore after discussions with the TWG Chairs, the security policy does not apply and there is no need to report the findings as a vulnerability according to the policy.
Findings come from a review of pre-draft, re-verified at f6c2305a28 (2026‑08‑27) after #194 and #25 merged and after #205 (RFC 9457 problem details) and #211 were opened.
| ID |
Severity |
Title |
| 01 |
High |
Require an explicit origin allowlist for trustBundleUri |
| 02 |
High |
Restore rollback detection and add a staleness signal after spiffe_sequence removal |
| 03 |
High |
No replay protection: constrain TLS 1.3 early data on the Management Interface |
| 04 |
High |
Require integrity protection of cached trust material at rest |
| 05 |
High |
Desired state cannot pin a workload artifact by immutable digest |
| 06 |
Medium |
Define what a device MUST refuse in a Compose workload, and pin the Compose Specification version |
| 07 |
High |
MIAF sets no floor for key protection or SVID lifetime |
| 08 |
Medium |
Secure the proxy-to-backend hop in TLS-offload topologies, per RFC 9440 Section 4 |
| 09 |
Medium |
Add verification guardrails for PKCS#1 v1.5 signatures and ECDSA nonce generation |
| 10 |
Medium |
Constrain Trust Bundle anchor entries: x5c count, JWK binding, and CA-ness |
| 11 |
Medium |
Require an authenticated time source or an anti-rollback store for certificate validation |
| 12 |
Medium |
Define a minimal MIAF audit event set |
| 13 |
Medium |
State that identity failure halts the management plane but does not stop running workloads |
| 14 |
Medium |
Bound certificate chain depth and presented-chain size |
| 15 |
Medium |
State the security cost of a shared wfm-id, and require per-instance key pairs |
| 16 |
Medium |
Define testable output constraints for MIS conformance |
| 17 |
Medium |
Bound Compose Archive entry count, uncompressed size and compression ratio |
| 18 |
Medium |
revision comparison is ambiguous: the tag mapping is lossy and SemVer precedence ignores build metadata |
| 19 |
Medium |
DeviceId permits . and .. path segments |
| 20 |
Low |
Bundle endpoint resilience: pin rotation, refresh jitter and bound, rate limiting |
| 21 |
Low |
TLS 1.2 fallback opt-in, and an unregistered problem type in the 403 example |
| 22 |
Low |
Enforce the /margo/ namespace at issuance, and a question about the removed body type discriminator |
| 23 |
Low |
State a hybrid key-exchange position and the chain-size implications of PQ signatures |
| 24 |
Informational |
Add a threat row for a compromised or malicious see-thru gateway |
| 25 |
Low |
Endpoint 404 wording contradicts the caller-scoping rule, and two navigation manifests are wrong |
| 26 |
Strategic |
Authenticated supply chain: signed desired state and attestation-backed issuance |
| 27 |
Low |
Identity concepts pages: late-binding cost, TLS-offload hop owner, bootstrap authentication in the diagram |
| 28 |
Low |
The inspection exemption asks operators to deviate from their own IEC 62443 zone-and-conduit policy |
Detailed explanations to each finding are provided in the attached filed 00-consolidated-issue.md.
Proposed fix
Proposed solutions are incorporated in the explanation file 00-consolidated-issue.md.
Anything else (optional)
No response
Bug description
Findings are all related to the Margo (pre-draft) specification, not to any implementation / executable code. Therefore after discussions with the TWG Chairs, the security policy does not apply and there is no need to report the findings as a vulnerability according to the policy.
Findings come from a review of
pre-draft, re-verified atf6c2305a28(2026‑08‑27) after #194 and #25 merged and after #205 (RFC 9457 problem details) and #211 were opened.trustBundleUrispiffe_sequenceremovalx5ccount, JWK binding, and CA-nesswfm-id, and require per-instance key pairsrevisioncomparison is ambiguous: the tag mapping is lossy and SemVer precedence ignores build metadataDeviceIdpermits.and..path segments/margo/namespace at issuance, and a question about the removed body type discriminatorDetailed explanations to each finding are provided in the attached filed 00-consolidated-issue.md.
Proposed fix
Proposed solutions are incorporated in the explanation file 00-consolidated-issue.md.
Anything else (optional)
No response