As a U.S. government agency, we are committed to protecting the public’s information, including financial and personal information, from unauthorized disclosure.
Security researchers should feel comfortable reporting vulnerabilities discovered under this policy so we have the opportunity to remediate the findings and keep information safe.
This policy describes what systems and types of research we cover, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.
What you can test
This policy applies to the systems in the “Scopes” section identified on the VDP Platform.
We exclude any services not expressly listed, including connected services, from this policy’s scope, and we do not authorize testing on them. Report vulnerabilities you find in vendors’ non-federal systems directly to the vendor according to their disclosure policy, if any. If you aren’t sure whether a system or endpoint is in scope, contact us at gsa-vulnerability-reports@gsa.gov before starting your research.
We do not authorize the following test types:
- User interface bugs or typos.
- Network denial of service tests.
- Physical testing, such as office access, open doors, tailgating, social engineering, or any other non-technical vulnerability testing.
- Brute force attacks against login interfaces.
If you encounter any of the following on our systems while testing within the scope of this policy, stop your test and notify us immediately. Do not disclose any of the following to third parties:
- Personally identifiable information, or PII.
- Financial information, such as credit card or bank account numbers.
- Proprietary information or trade secrets belonging to any party.
How to test responsibly
Security researchers shall:
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
- Use exploits to the extent necessary to confirm a vulnerability. Do not use an exploit to compromise or exfiltrate data, establish command line access or persistence, or “pivot” to other systems. Once you’ve confirmed a vulnerability or encountered any of the sensitive data we listed above, stop your test and notify us immediately.
- Keep confidential any information about vulnerabilities you discover for up to 90 calendar days after notifying us. See when and how you disclose publicly for details.
We commit to acknowledging receipt of the report within two business days via the CISA VDP Platform.
Your legal protections
You must comply with all applicable federal, state, and local laws when conducting security research or otherwise participating in this vulnerability disclosure program.
We do not authorize, permit, or otherwise allow, expressly or impliedly, any individual, group, consortium, partnership, or other business or legal entity to engage in any security research, vulnerability, or threat disclosure activity that is inconsistent with this policy or the law. If you engage in activities inconsistent with this policy or the law, you may face criminal and or civil liability.
If your security research or vulnerability disclosure activity involves the networks, systems, information, applications, products, or services of an entity other than us, such as other federal departments or agencies; state, local, or tribal governments; private sector companies or individuals; or any other third party, that entity may independently decide whether to pursue legal action related to those activities.
If you conduct your research and disclosure activities in accordance with this policy:
- We will not initiate or recommend law enforcement or civil action related to those activities
- We will, absent any legal restriction, confirm that you conducted your activities in compliance with this policy if someone other than us brings a law enforcement or civil action.
How to report a vulnerability
Email vulnerability reports to gsa-vulnerability-reports@gsa.gov or submit them via the CISA VDP Platform.
Note: We do not support Pretty Good Privacy, or PGP-encrypted emails. Do not share sensitive information through email. If you believe it is necessary to share sensitive information with us, note this in your report, and we will contact you to establish a more secure method.
Include the following in your report:
- Description of the location and potential impact of the vulnerability.
- A detailed description of the steps required to reproduce the vulnerability. Proof of concept (POC) scripts, screenshots, and screen captures are all helpful. Please use extreme care to properly label and protect any exploit code.
- Any technical information and related materials we would need to reproduce the issue.
Please keep your report current by sending us new information as it becomes available. We may share your vulnerability reports with the Cybersecurity and Infrastructure Security Agency, and any affected vendors or open source projects.
When and how you can disclose publicly
We are committed to patching vulnerabilities within 90 days or less and disclosing details once we publish patches. We believe public disclosure of vulnerabilities is an essential part of the vulnerability disclosure process, and one of the best ways to improve software is to let everyone learn from each other’s mistakes.
At the same time, disclosure without a readily available patch tends to increase risk rather than reduce it. We ask that you refrain from sharing your report with others while we work on a patch. If you believe others should be informed of your report before the patch is available, let us know so we can make arrangements.
We may want to coordinate an advisory to publish simultaneously with the patch, but you’re welcome to self-disclose if you prefer. By default, we prefer to disclose everything, but we will never publish information about you or our communications with you without your permission. In some cases, we may need to redact sensitive information, so please check with us before self-disclosing.