Green Hat Security · Public policy
Vulnerability Disclosure & CVE Coordination Policy
How Green Hat receives authorized vulnerability reports, coordinates with suppliers and appropriate CVE Program participants, protects sensitive submissions, and publishes defensive advisories.
Current status: Green Hat Security is not currently a CVE Numbering Authority. Green Hat coordinates potential CVE assignments with the affected supplier, its designated CNA, or another appropriate CVE Program participant.
Policy foundation
Purpose
Green Hat Security conducts authorized vulnerability research and coordinates responsible disclosure of verified security vulnerabilities.
Our objective is to provide maintainers with actionable information, support effective remediation, recognize researchers appropriately, and leave defenders with accurate public vulnerability information.
Testing boundary
Authorization
This policy does not grant permission to test Green Hat Security, Green Hat clients, or third-party systems.
Green Hat accepts reports arising from:
- Systems the researcher owns or controls
- Local or isolated copies of open-source software
- Bug bounty or vulnerability disclosure programs that expressly authorize the testing performed
- Written authorization from the affected system owner
- Other environments where the researcher has clear legal authorization
Researchers are responsible for complying with the authorization and scope applicable to their testing.
What Green Hat accepts
Green Hat may coordinate third-party software vulnerabilities where:
- A reproducible security vulnerability exists
- The reporter can provide adequate technical evidence
- The issue was discovered through authorized research
- Coordinated disclosure would benefit affected users
- Another vulnerability-coordination process does not make Green Hat's involvement inappropriate
What Green Hat does not accept
Green Hat may decline:
- Reports resulting from unauthorized testing
- Reports without enough information to reproduce or understand the issue
- Purely theoretical issues without meaningful security consequences
- Spam or automated scanner output without validation
- Duplicate reports
- Issues already being appropriately handled by another CNA or disclosure coordinator
- Reports that would require Green Hat to violate another program's disclosure rules
Secure intake
Reporting a vulnerability
Submit reports through the secure form at /research/report.
Public contact: cve@greenhatsec.com
Service goals
Expected response targets
These are operational goals, not absolute guarantees. Complex, incomplete, or unusually sensitive reports may require more time.
- Acknowledgement
- Within 2 business days
- Initial scope and triage review
- Within 5 business days
- Material coordination update
- At least every 10 business days while actively coordinating
Operating process
Coordination process
Receive → Validate → Check CNA Scope → Notify Supplier → Coordinate → Publish
- 01
Receive
Verify that adequate contact and technical information have been provided.
- 02
Validate
Review the evidence, reproduce the issue where appropriate, identify affected products and versions, and determine whether the behavior appears to represent a vulnerability.
- 03
Check CNA scope
Determine whether another CNA has a more appropriate scope for the vulnerability.
- 04
Notify supplier
Make a reasonable effort to privately notify the affected supplier or maintainer.
- 05
Coordinate
Clarify affected versions, remediation, mitigation, disclosure timing, and the public information with relevant parties.
- 06
Publish
After coordinated disclosure, publish an advisory that helps affected users understand and remediate the vulnerability.
CVE Program relationship
CVE Coordination
Green Hat Security is not currently a CVE Numbering Authority.
Where a reported vulnerability appears appropriate for a CVE ID, Green Hat may coordinate with the affected supplier, its designated CNA, or another appropriate CVE Program participant.
Green Hat cannot independently reserve or assign CVE IDs unless and until Green Hat Security is formally authorized as a CNA. Green Hat does not promise that a report will receive a CVE ID.
Proposed CNA application scope
Green Hat Security products, and vulnerabilities identified by or reported to Green Hat Security through authorized vulnerability research or coordinated vulnerability disclosure, unless covered by the scope of another CVE Numbering Authority with more appropriate scope.
Embargo and timing
Coordinated Disclosure
Green Hat prefers coordinated disclosure that gives maintainers a reasonable opportunity to investigate and remediate vulnerabilities before technical details are made public.
A normal coordination period may be up to 90 days, but Green Hat may agree to shorter or longer timelines depending on:
- Vendor responsiveness
- Remediation complexity
- Availability of a fix
- Active exploitation
- Public knowledge of the vulnerability
- Risk to users
- Other disclosure programs governing the research
Green Hat may disclose earlier where continued confidentiality would create unreasonable risk to affected users or where the vulnerability is already public. Green Hat will attempt to coordinate the final public disclosure date with the supplier whenever practical.
Attribution
Researcher Credit
Green Hat aims to credit researchers accurately when they request public attribution. Supported choices include full legal name, researcher handle, organization, name and handle, or anonymous attribution.
Example: Anthony Green [antnation] — Green Hat Security
A researcher may request anonymity before publication. Credit does not imply employment, partnership, endorsement, or affiliation unless that relationship actually exists.
Record integrity
Corrections and Disputes
Researchers, vendors, maintainers, and affected parties may contact Green Hat about:
- Incorrect affected-version information
- Incorrect vulnerability descriptions
- Attribution errors
- Duplicate CVE assignments
- Disputed vulnerability determinations
- CVE scope questions
- Rejected or disputed CVE assignments
- Remediation updates
Contact cve@greenhatsec.com. Green Hat will review substantiated corrections and update its advisory where appropriate.
Data handling
Sensitive Information
Green Hat does not publish embargoed submissions.
Private vulnerability submissions must not be placed in public GitHub issues, client-side analytics, public logging platforms, public CMS fields, or public support tickets. Access is restricted to personnel involved in vulnerability coordination.
If a report includes secrets, credentials, personal information, customer data, or other unnecessary sensitive information, Green Hat will minimize retention and securely remove it when it is no longer required.