RFC9116 — A File Format to Aid in Security Vulnerability Disclosure

provenance: imported · standards: RFC9116

RFC9116: A File Format to Aid in Security Vulnerability Disclosure

IETF Request for Comments

Status INFORMATIONAL
Publication status INFORMATIONAL
Published April 2022
Stream IETF
Obsoletes —
Obsoleted by —
Updated by —

Abstract

When security vulnerabilities are discovered by researchers, proper reporting channels are often lacking. As a result, vulnerabilities may be left unreported. This document defines a machine-parsable format ("security.txt") to help organizations describe their vulnerability disclosure practices to make it easier for researchers to report vulnerabilities.

Official sources

  • Info page: https://www.rfc-editor.org/info/rfc9116
  • Full text: https://www.rfc-editor.org/rfc/rfc9116.txt
  • HTML: https://www.rfc-editor.org/rfc/rfc9116.html

Abstract and metadata are reproduced from the public RFC index; the full text is linked, not copied.

See all 29 pages under Internet standards (RFC) →