CarMax · Vulnerability Disclosure
Carmax Vulnerability Disclosure
Vulnerability disclosure
CarMax runs a coordinated vulnerability disclosure program on Hackerone.
Auto FinancingAuto RetailAppraisalsAutomotiveOmnichannelRetailServer-Driven UIUsed CarsVehicle InventoryVIN LookupFortune 500
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-05'
method: searched
source: https://www.carmax.com/.well-known/security.txt (archived 2026-02-03, status 200)
+ https://www.carmax.com/responsible-disclosure
provider: CarMax
providerId: carmax
program:
exists: true
type: responsible-disclosure
name: CarMax Responsible Disclosure for Security Vulnerabilities
policy_url: https://www.carmax.com/responsible-disclosure
contact: mailto:responsible_disclosure@carmax.com
bug_bounty: false
bounty_platform: null
preferred_languages: en
hiring: https://careers.carmax.com/us/en/search-results?keywords=cybersecurity
security_txt:
served: true
path: /.well-known/security.txt
file: ../well-known/carmax-security.txt
live_status: 403
archived_status: 200
archived_url: https://web.archive.org/web/20260203040122id_/https://www.carmax.com/.well-known/security.txt
fields:
Contact: mailto:responsible_disclosure@carmax.com
Expires: '2024-12-31T05:00:00.000Z'
Preferred-Languages: en
Hiring: https://careers.carmax.com/us/en/search-results?keywords=cybersecurity
rfc9116_issues:
- id: expired
detail: >-
The "Expires" field is 2024-12-31T05:00:00.000Z. Under RFC 9116 a security.txt
past its Expires value should not be relied on; CarMax has not refreshed it.
- id: no-policy-field
detail: >-
No "Policy" field, although CarMax does publish a policy page at
/responsible-disclosure. Adding "Policy: https://www.carmax.com/responsible-disclosure"
would make the two documents point at each other.
- id: no-canonical-field
detail: No "Canonical" field.
evidence:
- url: https://www.carmax.com/.well-known/security.txt
status: 403
note: live probe 2026-09-05 — Akamai bot-manager refusal, not absence
- url: https://web.archive.org/web/20260203040122id_/https://www.carmax.com/.well-known/security.txt
status: 200
note: verbatim RFC 9116 body, saved to well-known/carmax-security.txt
- url: https://www.carmax.com/responsible-disclosure
status: 403
note: live probe 2026-09-05 refused; Wayback capture 2026-08-22 returns status 200
with the title "CarMax Responsible Disclosure for Security Vulnerabilities" and a
"Report vulnerability" action. The page body is client-rendered, so the archived
HTML carries the title only.
notes: >-
CarMax runs a coordinated vulnerability-disclosure program with a dedicated intake
address and a published policy page. There is no paid bug bounty and no HackerOne,
Bugcrowd or Intigriti listing was found. The one gap worth reporting back to CarMax
is the expired security.txt.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carmax-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.