Cardinal Health · Vulnerability Disclosure
Cardinal Health Vulnerability Disclosure
Vulnerability disclosure
Cardinal Health runs a coordinated vulnerability disclosure program on Hackerone.
B2BDistributionEDIHealthcareMedical-SurgicalOrder-to-CashPharmaceuticalsSupply ChainTrading PartnerFortune 100
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-05'
method: searched
source: https://hackerone.com/cardinal_health
provider: Cardinal Health
providerId: cardinal-health
program:
present: true
name: Cardinal Health Vulnerability Disclosure Policy
platform: HackerOne
handle: cardinal_health
url: https://hackerone.com/cardinal_health
type: vulnerability-disclosure-program
bounty: unknown
note: >-
HackerOne renders the program page client-side, so the policy text, scope table
and bounty status could not be read anonymously. Presence is confirmed by a
fetched 200 whose body carries the string "Cardinal Health", verified against a
negative control on a handle that does not exist, which returned 404 with the
title "Page not found | HackerOne".
evidence:
- url: https://hackerone.com/cardinal_health
http_status: 200
bytes: 2295
fetched: '2026-09-05'
check: body contains "Cardinal Health"
- url: https://hackerone.com/zzz_not_a_real_program_7f3ab91c
http_status: 404
bytes: 1694
fetched: '2026-09-05'
check: negative control — a nonexistent handle 404s, so the 200 above is a real program
disclosure_pages:
- title: Coordinated Vulnerability Disclosure (CVD)
url: https://www.cardinalhealth.com/en/support/coordinated-vulnerability-disclosure.html
verified: false
http_status: null
note: >-
First-party Cardinal Health CVD page, surfaced by search and indexed publicly.
NOT fetched this round: www.cardinalhealth.com completes the TLS handshake and
then drops every non-browser connection (curl exit 000, fetch tool 60s timeout),
so no status code was observed and no content was read. Recorded as an
unverified reference rather than a confirmed document; it is a bot-mitigation
wall on our side, not evidence the page is gone.
security_txt:
served: false
note: >-
/.well-known/security.txt is not served on any reachable Cardinal Health host.
See well-known/cardinal-health-well-known.yml — the three reachable web hosts are
catch-all shells that answer 200 for a control path that cannot exist, and
api.cardinalhealth.com returns 403 VPC Service Controls for every path.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cardinal-health-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.