RFC 9116

A File Format to Aid in Security Vulnerability Disclosure, April 2022

File formats:

icon for HTML icon for text file icon for v3pdf icon for XML icon for inline errata
Status:
INFORMATIONAL
Authors:
E. Foudil
Y. Shafranovich
Stream:
IETF
Source:
NON WORKING GROUP

Cite this RFC: TXT  |  XML

DOI:  10.17487/RFC9116

Discuss this RFC: Send questions or comments to iesg@ietf.org

Other actions: View Errata  |  Submit Errata  |  Find IPR Disclosures from the IETF  |  View History of RFC 9116


Abstract

When security vulnerabilities are discovered by researchers, proper reporting channels are often lacking. As a result, vulnerabilities may be left unreported. This document defines a machine-parsable format ("security.txt") to help organizations describe their vulnerability disclosure practices to make it easier for researchers to report vulnerabilities.


For the definition of Status, see RFC 2026.

For the definition of Stream, see RFC 8729.




Advanced Search