Artemis · Vulnerability Disclosure
Artemis Vulnerability Disclosure
Vulnerability disclosure
Artemis runs a coordinated vulnerability disclosure program on Bugcrowd.
ExplorationLunarMoonNASASpaceGovernment
Program: Bugcrowd
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-04'
method: searched
source: https://www.nasa.gov/vulnerability-disclosure-policy/
note: >-
probe-security-programs.py found nothing for this record because NASA serves no
/.well-known/security.txt on any host. The program exists anyway — it is published as an HTML
policy page plus a public Bugcrowd engagement, both fetched and confirmed live. Recorded by hand
with the URLs actually probed.
program:
exists: true
name: NASA Vulnerability Disclosure Policy
policy_url: https://www.nasa.gov/vulnerability-disclosure-policy/
policy_http_status: 200
policy_pdf: https://www.nasa.gov/wp-content/uploads/2026/05/vulnerability-disclosure-policy-1-6-2.pdf
submission_platform: Bugcrowd
submission_url: https://bugcrowd.com/engagements/nasa-vdp
submission_http_status: 200
bounty: false
type: coordinated disclosure (no monetary reward)
legal_basis: CISA Binding Operational Directive 20-01, which requires every US federal civilian agency to publish a vulnerability disclosure policy
security_txt:
published: false
probed:
- url: https://www.nasa.gov/.well-known/security.txt
status: 404
- url: https://nasa.gov/.well-known/security.txt
status: 404
- url: https://api.nasa.gov/.well-known/security.txt
status: 404
- url: https://technology.nasa.gov/.well-known/security.txt
status: 404
- url: https://trek.nasa.gov/.well-known/security.txt
status: 404
- url: https://techport.nasa.gov/.well-known/security.txt
status: 200
note: SPA catch-all returning the TechPort Angular index.html, not a security.txt. A miss.
gap: >-
The one machine-readable artifact this program is missing. NASA has a real, mandated, staffed
disclosure channel and no /.well-known/security.txt pointing at it, so an automated scanner —
including this pipeline's own probe — concludes there is no program. A four-line file at
www.nasa.gov/.well-known/security.txt naming the policy URL and the Bugcrowd engagement would
close it. This is the highest-leverage, lowest-cost fix available on this surface.
evidence:
- url: https://www.nasa.gov/vulnerability-disclosure-policy/
status: 200
fetched: '2026-09-04'
- url: https://bugcrowd.com/engagements/nasa-vdp
status: 200
fetched: '2026-09-04'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/artemis-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.