Comcast · Vulnerability Disclosure

Comcast Vulnerability Disclosure

Vulnerability disclosure

Comcast runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

CableConnected DevicesEntertainmentInternetMediaMobileStreamingWirelessFortune 100
Program: Bugcrowd

Disclosure Policy

Security Contact

Contact
emailsecuritydefectreporting@comcast.com
Contact
form_platformBugcrowd
Contact
pgptrue
Contact
web_formhttps://www.xfinity.com/vulnerabilityreport

Source

Vulnerability Disclosure

comcast-vulnerability-disclosure.yml Raw ↑
# Comcast — vulnerability disclosure program
#
# probe-security-programs.py returned vdp=none for this slug because Comcast
# serves no /.well-known/security.txt on any host in this record (probed
# 2026-09-05 — see well-known/comcast-well-known.yml). The program nevertheless
# exists and is substantial; it is simply not discoverable at the RFC 9116 path.
# Upgraded to method: searched from the provider's own published policy page.
generated: '2026-09-05'
method: searched
source: https://www.xfinity.com/vulnerabilityreport (HTTP 200, fetched 2026-09-05)
provider: Comcast
providerId: comcast
published: true
policy_url: https://www.xfinity.com/vulnerabilityreport
policy_url_status: 200
security_txt: false
security_txt_note: >-
  No /.well-known/security.txt served on comcast.com, www.comcast.com,
  www.xfinity.com, developers.xfinity.com, docs.developer.comcast.com,
  developer.comcast.com or either codebig2.net API host. This is a real
  discoverability gap: a machine looking for the program at the standard path
  will not find it, and www.comcast.com additionally answers 406 to crawlers.
contact:
  email: securitydefectreporting@comcast.com
  pgp: true
  web_form: https://www.xfinity.com/vulnerabilityreport
  form_platform: Bugcrowd
platforms:
  - platform: Bugcrowd
    programs:
      - name: Comcast Xfinity Vulnerability Disclosure Program
        url: https://bugcrowd.com/engagements/comcastvdp
        status: 200
      - name: Xfinity Home & xFi
        url: https://bugcrowd.com/engagements/xfinity-home
        status: 200
      - name: Comcast MBB
        url: https://bugcrowd.com/engagements/comcast-mbb
rewards:
  offered: true
  guaranteed: false
  statement: >-
    "not all submissions are eligible for a reward; eligibility depends on the
    merit, quality, and impact of the findings."
scope_definition: >-
  Comcast defines a security vulnerability as "an unintended weakness or
  exposure that could be used to compromise the integrity, availability or
  confidentiality of our products and services." Reports are accepted from
  independent researchers, industry partners, vendors, customers and
  consultants.
principles:
  - Trust — confidentiality is maintained in exchanges with researchers.
  - Respect — researchers are asked to avoid privacy violations, degradation of user experience, disruption of production systems and destruction of data.
  - Transparency — researchers provide the technical detail needed to validate a report.
  - Common Good — no public disclosure of unverified vulnerabilities before validation.
related:
  research_program: https://corporate.comcast.com/cybersecurity/ccs-research
  research_program_status: 200
covers_developer_platform: unknown
covers_developer_platform_note: >-
  The policy is written for Comcast/Xfinity products and services generally. It
  does not name the Firebolt developer platform, docs.developer.comcast.com or
  the codebig2.net API hosts in scope, and the Bugcrowd scopes were not readable
  anonymously. No claim is made either way.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/comcast-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.