Carvana · Vulnerability Disclosure
Carvana Vulnerability Disclosure
Vulnerability disclosure
Carvana runs a coordinated vulnerability disclosure program on Bugcrowd.
AutomotiveE-CommerceUsed CarsInventoryPartner APIFortune 500
Program: Bugcrowd
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-05'
method: searched
probe: true
source: https://www.carvana.com/responsible-disclosure
program:
name: Carvana Responsible Disclosure Policy
url: https://www.carvana.com/responsible-disclosure
status: published
platform: Bugcrowd
platform_program_id: 7aff569d-7f85-47e6-9475-061e43445987
submission_url: https://bugcrowd.com/7aff569d-7f85-47e6-9475-061e43445987/external/report
submission_channel: >-
A Bugcrowd-hosted external report form is embedded at the bottom of the Responsible Disclosure
page (script src https://bugcrowd.com/7aff569d-7f85-47e6-9475-061e43445987/external/script). No
security@ address, no PGP key and no /.well-known/security.txt is published — the form is the
only intake channel.
rewards: >-
Monetary compensation is offered but not quantified. The policy states a researcher must include
detailed reproduction steps "in order for a security researcher to be considered for monetary
compensation" — there is no published bounty table.
safe_harbor: >-
Yes. "We will not take legal action against, or suspend or terminate the accounts of, researchers
who discover and report security vulnerabilities in accordance with this Policy." Carvana
reserves all legal rights on non-compliance.
coordinated_disclosure: >-
Public disclosure without express written consent from Carvana's InfoSec Team makes a submission
non-compliant with the policy. No stated disclosure clock.
commitments:
- Work with the researcher to understand and validate the suspected vulnerability
- Address any valid vulnerability or risk as Carvana deems necessary and appropriate
ineligible_reporters:
- Carvana employees
- Carvana subsidiaries, affiliates or partners
- Vendors working with or for Carvana or its subsidiaries, affiliates or partners
- Residents of countries on the US OFAC Sanctions List
prohibited_testing:
- Accessing, downloading or modifying data in an account the researcher does not own
- Denial-of-service or related attacks against any Carvana system or service
- Posting, transmitting or storing malicious software on any Carvana system or service
- Testing that results in unsolicited or unauthorized junk mail, spam or pyramid schemes
- Testing that degrades or negatively impacts the operation of any Carvana service or system
- Testing third-party applications, websites or services that integrate with or link to Carvana
evidence:
- source: https://www.carvana.com/responsible-disclosure
kind: disclosure page
http_status: 200
fetched: '2026-09-05'
keywords:
- vulnerability
- responsible disclosure
- security research
- bugcrowd
- monetary compensation
- safe harbor
- source: https://www.carvana.com/.well-known/security.txt
kind: RFC 9116 negative probe
http_status: 404
fetched: '2026-09-05'
note: >-
Carvana runs a real disclosure programme but does not advertise it at the machine-readable
path. An agent or scanner that looks only for /.well-known/security.txt will conclude Carvana
has no programme. This is the single cheapest fix available to them.
maintainers:
- FN: Kin Lane
email: info@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carvana-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.