Cardinal Health · Vulnerability Disclosure

Cardinal Health Vulnerability Disclosure

Vulnerability disclosure

Cardinal Health runs a coordinated vulnerability disclosure program on Hackerone.

B2BDistributionEDIHealthcareMedical-SurgicalOrder-to-CashPharmaceuticalsSupply ChainTrading PartnerFortune 100
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

cardinal-health-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
source: https://hackerone.com/cardinal_health
provider: Cardinal Health
providerId: cardinal-health
program:
  present: true
  name: Cardinal Health Vulnerability Disclosure Policy
  platform: HackerOne
  handle: cardinal_health
  url: https://hackerone.com/cardinal_health
  type: vulnerability-disclosure-program
  bounty: unknown
  note: >-
    HackerOne renders the program page client-side, so the policy text, scope table
    and bounty status could not be read anonymously. Presence is confirmed by a
    fetched 200 whose body carries the string "Cardinal Health", verified against a
    negative control on a handle that does not exist, which returned 404 with the
    title "Page not found | HackerOne".
evidence:
  - url: https://hackerone.com/cardinal_health
    http_status: 200
    bytes: 2295
    fetched: '2026-09-05'
    check: body contains "Cardinal Health"
  - url: https://hackerone.com/zzz_not_a_real_program_7f3ab91c
    http_status: 404
    bytes: 1694
    fetched: '2026-09-05'
    check: negative control — a nonexistent handle 404s, so the 200 above is a real program
disclosure_pages:
  - title: Coordinated Vulnerability Disclosure (CVD)
    url: https://www.cardinalhealth.com/en/support/coordinated-vulnerability-disclosure.html
    verified: false
    http_status: null
    note: >-
      First-party Cardinal Health CVD page, surfaced by search and indexed publicly.
      NOT fetched this round: www.cardinalhealth.com completes the TLS handshake and
      then drops every non-browser connection (curl exit 000, fetch tool 60s timeout),
      so no status code was observed and no content was read. Recorded as an
      unverified reference rather than a confirmed document; it is a bot-mitigation
      wall on our side, not evidence the page is gone.
security_txt:
  served: false
  note: >-
    /.well-known/security.txt is not served on any reachable Cardinal Health host.
    See well-known/cardinal-health-well-known.yml — the three reachable web hosts are
    catch-all shells that answer 200 for a control path that cannot exist, and
    api.cardinalhealth.com returns 403 VPC Service Controls for every path.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cardinal-health-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.