Skip to content

Archive

Vulnerability Disclosure

2 articles
Cybersecurity 24 Sep 2026 6 min read

security.txt Publishes a Machine-Readable Vulnerability Contact

A vulnerability report can lose value before triage begins if the reporter cannot identify a current, organization-controlled contact. RFC 9116 addresses that routing problem with security.txt, a machine-parsable text file published at a predictable HTTPS location. The file does not grant testing permission, establish a bug bounty, or prove that a listed recipient is trustworthy. Its narrower role is to publish vulnerability disclosure metadata in a format that people and automated tools can retrieve consistently.

Cybersecurity 24 Sep 2026 5 min read

security.txt Publishes a Bounded Vulnerability Reporting Route

A security flaw can be difficult to report even when the affected service is easy to identify. A generic support form may route the message to the wrong queue, an old security mailbox may no longer be staffed, and a researcher cannot safely infer disclosure policy from a company name alone. RFC 9116 addresses that routing problem with security.txt, a small machine-parsable file published by the service operator. The file does not certify that a service is secure, authorize testing, or define a complete vulnerability disclosure program. Its narrower job is to publish current reporting coordinates and related metadata at a predictable location.