Green Hat Security · Public policy

Vulnerability Disclosure & CVE Coordination Policy

How Green Hat receives authorized vulnerability reports, coordinates with suppliers and appropriate CVE Program participants, protects sensitive submissions, and publishes defensive advisories.

Current status: Green Hat Security is not currently a CVE Numbering Authority. Green Hat coordinates potential CVE assignments with the affected supplier, its designated CNA, or another appropriate CVE Program participant.

Purpose

Green Hat Security conducts authorized vulnerability research and coordinates responsible disclosure of verified security vulnerabilities.

Our objective is to provide maintainers with actionable information, support effective remediation, recognize researchers appropriately, and leave defenders with accurate public vulnerability information.

Authorization

This policy does not grant permission to test Green Hat Security, Green Hat clients, or third-party systems.

Green Hat accepts reports arising from:

  • Systems the researcher owns or controls
  • Local or isolated copies of open-source software
  • Bug bounty or vulnerability disclosure programs that expressly authorize the testing performed
  • Written authorization from the affected system owner
  • Other environments where the researcher has clear legal authorization

Researchers are responsible for complying with the authorization and scope applicable to their testing.

What Green Hat accepts

Green Hat may coordinate third-party software vulnerabilities where:

  • A reproducible security vulnerability exists
  • The reporter can provide adequate technical evidence
  • The issue was discovered through authorized research
  • Coordinated disclosure would benefit affected users
  • Another vulnerability-coordination process does not make Green Hat's involvement inappropriate

What Green Hat does not accept

Green Hat may decline:

  • Reports resulting from unauthorized testing
  • Reports without enough information to reproduce or understand the issue
  • Purely theoretical issues without meaningful security consequences
  • Spam or automated scanner output without validation
  • Duplicate reports
  • Issues already being appropriately handled by another CNA or disclosure coordinator
  • Reports that would require Green Hat to violate another program's disclosure rules

Reporting a vulnerability

Submit reports through the secure form at /research/report.

Public contact: cve@greenhatsec.com

Do not submit embargoed vulnerability details through ordinary website contact forms, social media, LinkedIn, or public issue trackers.

Expected response targets

These are operational goals, not absolute guarantees. Complex, incomplete, or unusually sensitive reports may require more time.

Acknowledgement
Within 2 business days
Initial scope and triage review
Within 5 business days
Material coordination update
At least every 10 business days while actively coordinating

Coordination process

Receive → Validate → Check CNA Scope → Notify Supplier → Coordinate → Publish

  1. 01

    Receive

    Verify that adequate contact and technical information have been provided.

  2. 02

    Validate

    Review the evidence, reproduce the issue where appropriate, identify affected products and versions, and determine whether the behavior appears to represent a vulnerability.

  3. 03

    Check CNA scope

    Determine whether another CNA has a more appropriate scope for the vulnerability.

  4. 04

    Notify supplier

    Make a reasonable effort to privately notify the affected supplier or maintainer.

  5. 05

    Coordinate

    Clarify affected versions, remediation, mitigation, disclosure timing, and the public information with relevant parties.

  6. 06

    Publish

    After coordinated disclosure, publish an advisory that helps affected users understand and remediate the vulnerability.

CVE Coordination

Green Hat Security is not currently a CVE Numbering Authority.

Where a reported vulnerability appears appropriate for a CVE ID, Green Hat may coordinate with the affected supplier, its designated CNA, or another appropriate CVE Program participant.

Green Hat cannot independently reserve or assign CVE IDs unless and until Green Hat Security is formally authorized as a CNA. Green Hat does not promise that a report will receive a CVE ID.

Proposed CNA application scope

Green Hat Security products, and vulnerabilities identified by or reported to Green Hat Security through authorized vulnerability research or coordinated vulnerability disclosure, unless covered by the scope of another CVE Numbering Authority with more appropriate scope.

Coordinated Disclosure

Green Hat prefers coordinated disclosure that gives maintainers a reasonable opportunity to investigate and remediate vulnerabilities before technical details are made public.

A normal coordination period may be up to 90 days, but Green Hat may agree to shorter or longer timelines depending on:

  • Vendor responsiveness
  • Remediation complexity
  • Availability of a fix
  • Active exploitation
  • Public knowledge of the vulnerability
  • Risk to users
  • Other disclosure programs governing the research

Green Hat may disclose earlier where continued confidentiality would create unreasonable risk to affected users or where the vulnerability is already public. Green Hat will attempt to coordinate the final public disclosure date with the supplier whenever practical.

Researcher Credit

Green Hat aims to credit researchers accurately when they request public attribution. Supported choices include full legal name, researcher handle, organization, name and handle, or anonymous attribution.

Example: Anthony Green [antnation] — Green Hat Security

A researcher may request anonymity before publication. Credit does not imply employment, partnership, endorsement, or affiliation unless that relationship actually exists.

Corrections and Disputes

Researchers, vendors, maintainers, and affected parties may contact Green Hat about:

  • Incorrect affected-version information
  • Incorrect vulnerability descriptions
  • Attribution errors
  • Duplicate CVE assignments
  • Disputed vulnerability determinations
  • CVE scope questions
  • Rejected or disputed CVE assignments
  • Remediation updates

Contact cve@greenhatsec.com. Green Hat will review substantiated corrections and update its advisory where appropriate.

Sensitive Information

Green Hat does not publish embargoed submissions.

Private vulnerability submissions must not be placed in public GitHub issues, client-side analytics, public logging platforms, public CMS fields, or public support tickets. Access is restricted to personnel involved in vulnerability coordination.

If a report includes secrets, credentials, personal information, customer data, or other unnecessary sensitive information, Green Hat will minimize retention and securely remove it when it is no longer required.