CarMax · Vulnerability Disclosure

Carmax Vulnerability Disclosure

Vulnerability disclosure

CarMax runs a coordinated vulnerability disclosure program on Hackerone.

Auto FinancingAuto RetailAppraisalsAutomotiveOmnichannelRetailServer-Driven UIUsed CarsVehicle InventoryVIN LookupFortune 500
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

carmax-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
source: https://www.carmax.com/.well-known/security.txt (archived 2026-02-03, status 200)
  + https://www.carmax.com/responsible-disclosure
provider: CarMax
providerId: carmax
program:
  exists: true
  type: responsible-disclosure
  name: CarMax Responsible Disclosure for Security Vulnerabilities
  policy_url: https://www.carmax.com/responsible-disclosure
  contact: mailto:responsible_disclosure@carmax.com
  bug_bounty: false
  bounty_platform: null
  preferred_languages: en
  hiring: https://careers.carmax.com/us/en/search-results?keywords=cybersecurity
security_txt:
  served: true
  path: /.well-known/security.txt
  file: ../well-known/carmax-security.txt
  live_status: 403
  archived_status: 200
  archived_url: https://web.archive.org/web/20260203040122id_/https://www.carmax.com/.well-known/security.txt
  fields:
    Contact: mailto:responsible_disclosure@carmax.com
    Expires: '2024-12-31T05:00:00.000Z'
    Preferred-Languages: en
    Hiring: https://careers.carmax.com/us/en/search-results?keywords=cybersecurity
  rfc9116_issues:
  - id: expired
    detail: >-
      The "Expires" field is 2024-12-31T05:00:00.000Z. Under RFC 9116 a security.txt
      past its Expires value should not be relied on; CarMax has not refreshed it.
  - id: no-policy-field
    detail: >-
      No "Policy" field, although CarMax does publish a policy page at
      /responsible-disclosure. Adding "Policy: https://www.carmax.com/responsible-disclosure"
      would make the two documents point at each other.
  - id: no-canonical-field
    detail: No "Canonical" field.
evidence:
- url: https://www.carmax.com/.well-known/security.txt
  status: 403
  note: live probe 2026-09-05 — Akamai bot-manager refusal, not absence
- url: https://web.archive.org/web/20260203040122id_/https://www.carmax.com/.well-known/security.txt
  status: 200
  note: verbatim RFC 9116 body, saved to well-known/carmax-security.txt
- url: https://www.carmax.com/responsible-disclosure
  status: 403
  note: live probe 2026-09-05 refused; Wayback capture 2026-08-22 returns status 200
    with the title "CarMax Responsible Disclosure for Security Vulnerabilities" and a
    "Report vulnerability" action. The page body is client-rendered, so the archived
    HTML carries the title only.
notes: >-
  CarMax runs a coordinated vulnerability-disclosure program with a dedicated intake
  address and a published policy page. There is no paid bug bounty and no HackerOne,
  Bugcrowd or Intigriti listing was found. The one gap worth reporting back to CarMax
  is the expired security.txt.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carmax-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.