We read other people’s vulnerabilities all day.
Tell us about ours.
The whole CVE firehose crosses our desks. It would be a poor look to leave the same gap open in our own house — so if you have found a weakness in dbcve.org, we want it, and we will treat you the way we would want to be treated.
In scope
- dbcve.org and every page under it
- The public API and JSON endpoints
- Authentication — sign-in, sessions, account takeover
- The community layer — notes, votes, moderation bypass
- The scanner — github.com/DBCVE-org/cve-scanner
- Anything that exposes another customer’s data or an unpublished engagement
Out of scope
- Missing headers or cookie flags with no demonstrated impact
- Rate limiting on public, unauthenticated pages
- Self-XSS, clickjacking on pages with no state-changing action
- Findings from automated scanners with no working proof
- Reports about CVEs in the database — those belong to the vendor, not us
- Social engineering, physical access, or anything that degrades the service for others
The deal
Act in good faith under this policy and we will not pursue legal action, and will not report you. Take only the data you need to demonstrate the issue, and stop there.
A person reads every report and replies. You will hear from us on the timeline above — including if the answer is “we are not fixing this, and here is why”. No radio silence.
Once it is closed, tell us how you want to be credited: name, handle, or not at all. Your call, and we will not publish anything about the report before you are ready.
Responsible disclosure, in plain terms.
Good-faith research is welcome
Act in good faith under this policy and we won’t pursue legal action or report you. Don’t access more data than you need to demonstrate the issue, and don’t degrade the service for others.
We’ll respond
We acknowledge reports promptly, keep you updated as we investigate, and let you know when a fix ships. No radio silence.
Credit, however you want it
Once an issue is resolved, tell us how you’d like to be credited — by name, by handle, or not at all. Your call.
Scope
dbcve.org and its subdomains. Out of scope: volumetric or denial-of-service testing, social engineering of our team, physical attacks, and issues in third-party services we don’t control.
Found something? Tell us.
Reports come in through our support desk, so they’re tracked and land with our team rather than a black-hole inbox. Include as much detail as you can and we’ll take it from there — good-faith reports are always welcome.