RFC9116 — A File Format to Aid in Security Vulnerability Disclosure
RFC9116: A File Format to Aid in Security Vulnerability Disclosure
IETF Request for Comments
| Status | INFORMATIONAL |
| Publication status | INFORMATIONAL |
| Published | April 2022 |
| Stream | IETF |
| Obsoletes | — |
| Obsoleted by | — |
| Updated by | — |
Abstract
When security vulnerabilities are discovered by researchers, proper reporting channels are often lacking. As a result, vulnerabilities may be left unreported. This document defines a machine-parsable format ("security.txt") to help organizations describe their vulnerability disclosure practices to make it easier for researchers to report vulnerabilities.
Official sources
- Info page: https://www.rfc-editor.org/info/rfc9116
- Full text: https://www.rfc-editor.org/rfc/rfc9116.txt
- HTML: https://www.rfc-editor.org/rfc/rfc9116.html
Abstract and metadata are reproduced from the public RFC index; the full text is linked, not copied.