Civil Aviation Safety Authority (CASA) · Vulnerability Disclosure

Casa Aviation Vulnerability Disclosure

Vulnerability disclosure

Civil Aviation Safety Authority (CASA) publishes a vulnerability disclosure policy for reporting security issues.

TravelAustraliaAviationAirportsGovernmentRegulatorAviation SafetyOpen DataDrones
Program:

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

casa-aviation-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
summary: >-
  CASA publishes an External Security Vulnerability Disclosure Program. It covers
  any product or service CASA operates that a researcher has legitimate need to
  access, products/services/infrastructure shared with service partners, and
  third-party-owned services CASA uses as part of its own services. Reports are
  submitted through a CASA vulnerability reporting portal. CASA commits to
  assessing and treating reports under its internal procedures and, with the
  reporter's consent, to publicly acknowledging researchers whose report leads to a
  valid fix. CASA explicitly offers NO monetary reward and runs NO bug bounty.
policy:
  - https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
  - https://www.casa.gov.au/external-vulnerability-disclosure-program
policy_document:
  title: External Security Vulnerability Disclosure Program
  dated: July 2025
  classification: OFFICIAL
  format: PDF
contact: []
contact_note: >-
  Reports are made through CASA's vulnerability reporting portal form (fields
  include a description of the vulnerability and its impact, steps to replicate,
  and optional reporter name, phone and email) rather than to a published
  security@ address. No security.txt Contact: line exists - see
  well-known/casa-aviation-well-known.yml.
bug_bounty:
  offered: false
  platform: null
  statement: >-
    CASA does not offer monetary rewards or a bug bounty initiative. Recognition is
    public acknowledgement only, and only with the reporter's consent.
scope:
  in_scope:
    - Any product or service CASA operates that the reporter has legitimate need to access
    - Products, services and infrastructure shared with CASA service partners
    - Services third parties own that CASA uses as part of its services
  prohibited_activities:
    - Publicly disclosing vulnerability information
    - Modifying, destroying, exfiltrating or retaining data stored by CASA
casa_commitments:
  - Assess and treat the vulnerability report in line with internal procedures
  - Following replication and confirmation, begin measures to fix and mitigate
  - With reporter consent, publicly recognise and thank the reporter where the report leads to a valid security fix or identification of a vulnerability in a CASA-owned system
security_txt:
  published: false
  note: >-
    No /.well-known/security.txt was located. Probing www.casa.gov.au directly from
    this host is not possible (no response to programmatic clients), so its absence
    on www is unconfirmed; services.casa.gov.au and my.casa.gov.au both return 404.
evidence:
  - source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
    kind: disclosure-program-page
    retrieved_via: >-
      Search-engine index, 2026-07-28. Direct retrieval from the API Evangelist
      probe host was not possible: www.casa.gov.au returns no response to
      programmatic clients (HTTP/2 INTERNAL_ERROR, HTTP/1.1 timeout) and a public
      text-rendering proxy failed the same way. The page's existence, title, scope
      language, reporting process and no-bug-bounty statement are recorded from the
      indexed content.
  - source: https://www.casa.gov.au/external-vulnerability-disclosure-program
    kind: policy-pdf
    title: 'OFFICIAL External Security Vulnerability Disclosure Program July 2025'
  - source: probe-security-programs.py
    kind: automated-probe
    result: >-
      No hit. The probe checks /.well-known/security.txt and the conventional
      /security, /responsible-disclosure and /vulnerability-disclosure paths; CASA
      files its program under
      /about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program,
      which none of those patterns reach, and www.casa.gov.au does not answer the
      probe host in any case. Recorded so the automated miss is not read as an
      absence.