Carvana · Vulnerability Disclosure

Carvana Vulnerability Disclosure

Vulnerability disclosure

Carvana runs a coordinated vulnerability disclosure program on Bugcrowd.

AutomotiveE-CommerceUsed CarsInventoryPartner APIFortune 500
Program: Bugcrowd

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

carvana-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
probe: true
source: https://www.carvana.com/responsible-disclosure
program:
  name: Carvana Responsible Disclosure Policy
  url: https://www.carvana.com/responsible-disclosure
  status: published
  platform: Bugcrowd
  platform_program_id: 7aff569d-7f85-47e6-9475-061e43445987
  submission_url: https://bugcrowd.com/7aff569d-7f85-47e6-9475-061e43445987/external/report
  submission_channel: >-
    A Bugcrowd-hosted external report form is embedded at the bottom of the Responsible Disclosure
    page (script src https://bugcrowd.com/7aff569d-7f85-47e6-9475-061e43445987/external/script). No
    security@ address, no PGP key and no /.well-known/security.txt is published — the form is the
    only intake channel.
  rewards: >-
    Monetary compensation is offered but not quantified. The policy states a researcher must include
    detailed reproduction steps "in order for a security researcher to be considered for monetary
    compensation" — there is no published bounty table.
  safe_harbor: >-
    Yes. "We will not take legal action against, or suspend or terminate the accounts of, researchers
    who discover and report security vulnerabilities in accordance with this Policy." Carvana
    reserves all legal rights on non-compliance.
  coordinated_disclosure: >-
    Public disclosure without express written consent from Carvana's InfoSec Team makes a submission
    non-compliant with the policy. No stated disclosure clock.
  commitments:
    - Work with the researcher to understand and validate the suspected vulnerability
    - Address any valid vulnerability or risk as Carvana deems necessary and appropriate
  ineligible_reporters:
    - Carvana employees
    - Carvana subsidiaries, affiliates or partners
    - Vendors working with or for Carvana or its subsidiaries, affiliates or partners
    - Residents of countries on the US OFAC Sanctions List
  prohibited_testing:
    - Accessing, downloading or modifying data in an account the researcher does not own
    - Denial-of-service or related attacks against any Carvana system or service
    - Posting, transmitting or storing malicious software on any Carvana system or service
    - Testing that results in unsolicited or unauthorized junk mail, spam or pyramid schemes
    - Testing that degrades or negatively impacts the operation of any Carvana service or system
    - Testing third-party applications, websites or services that integrate with or link to Carvana
evidence:
  - source: https://www.carvana.com/responsible-disclosure
    kind: disclosure page
    http_status: 200
    fetched: '2026-09-05'
    keywords:
      - vulnerability
      - responsible disclosure
      - security research
      - bugcrowd
      - monetary compensation
      - safe harbor
  - source: https://www.carvana.com/.well-known/security.txt
    kind: RFC 9116 negative probe
    http_status: 404
    fetched: '2026-09-05'
    note: >-
      Carvana runs a real disclosure programme but does not advertise it at the machine-readable
      path. An agent or scanner that looks only for /.well-known/security.txt will conclude Carvana
      has no programme. This is the single cheapest fix available to them.
maintainers:
  - FN: Kin Lane
    email: info@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carvana-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.