Security & disclosure

We read other people’s vulnerabilities all day.
Tell us about ours.

The whole CVE firehose crosses our desks. It would be a poor look to leave the same gap open in our own house — so if you have found a weakness in dbcve.org, we want it, and we will treat you the way we would want to be treated.

24hWe acknowledge
5 daysWe triage and tell you what we found
90 daysFixed, or we explain why not
Do not post it in the community notes. Every CVE page here has a public comment box. Dropping an unfixed dbcve.org issue into one is a public disclosure, not a report — it puts every reader at risk before we can close it. Use the form or the email address.

In scope

  • dbcve.org and every page under it
  • The public API and JSON endpoints
  • Authentication — sign-in, sessions, account takeover
  • The community layer — notes, votes, moderation bypass
  • The scannergithub.com/DBCVE-org/cve-scanner
  • Anything that exposes another customer’s data or an unpublished engagement

Out of scope

  • Missing headers or cookie flags with no demonstrated impact
  • Rate limiting on public, unauthenticated pages
  • Self-XSS, clickjacking on pages with no state-changing action
  • Findings from automated scanners with no working proof
  • Reports about CVEs in the database — those belong to the vendor, not us
  • Social engineering, physical access, or anything that degrades the service for others

The deal

Safe harbour

Act in good faith under this policy and we will not pursue legal action, and will not report you. Take only the data you need to demonstrate the issue, and stop there.

We answer

A person reads every report and replies. You will hear from us on the timeline above — including if the answer is “we are not fixing this, and here is why”. No radio silence.

Credit, your way

Once it is closed, tell us how you want to be credited: name, handle, or not at all. Your call, and we will not publish anything about the report before you are ready.

The policy

Responsible disclosure, in plain terms.

Good-faith research is welcome

Act in good faith under this policy and we won’t pursue legal action or report you. Don’t access more data than you need to demonstrate the issue, and don’t degrade the service for others.

We’ll respond

We acknowledge reports promptly, keep you updated as we investigate, and let you know when a fix ships. No radio silence.

Credit, however you want it

Once an issue is resolved, tell us how you’d like to be credited — by name, by handle, or not at all. Your call.

Scope

dbcve.org and its subdomains. Out of scope: volumetric or denial-of-service testing, social engineering of our team, physical attacks, and issues in third-party services we don’t control.

Report it

Found something? Tell us.

Reports come in through our support desk, so they’re tracked and land with our team rather than a black-hole inbox. Include as much detail as you can and we’ll take it from there — good-faith reports are always welcome.