Comcast · Vulnerability Disclosure
Comcast Vulnerability Disclosure
Vulnerability disclosure
Comcast runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.
CableConnected DevicesEntertainmentInternetMediaMobileStreamingWirelessFortune 100
Program: Bugcrowd
Disclosure Policy
Security Contact
Contact
emailsecuritydefectreporting@comcast.com
Contact
form_platformBugcrowd
Contact
pgptrue
Contact
web_formhttps://www.xfinity.com/vulnerabilityreport
Source
Vulnerability Disclosure
# Comcast — vulnerability disclosure program
#
# probe-security-programs.py returned vdp=none for this slug because Comcast
# serves no /.well-known/security.txt on any host in this record (probed
# 2026-09-05 — see well-known/comcast-well-known.yml). The program nevertheless
# exists and is substantial; it is simply not discoverable at the RFC 9116 path.
# Upgraded to method: searched from the provider's own published policy page.
generated: '2026-09-05'
method: searched
source: https://www.xfinity.com/vulnerabilityreport (HTTP 200, fetched 2026-09-05)
provider: Comcast
providerId: comcast
published: true
policy_url: https://www.xfinity.com/vulnerabilityreport
policy_url_status: 200
security_txt: false
security_txt_note: >-
No /.well-known/security.txt served on comcast.com, www.comcast.com,
www.xfinity.com, developers.xfinity.com, docs.developer.comcast.com,
developer.comcast.com or either codebig2.net API host. This is a real
discoverability gap: a machine looking for the program at the standard path
will not find it, and www.comcast.com additionally answers 406 to crawlers.
contact:
email: securitydefectreporting@comcast.com
pgp: true
web_form: https://www.xfinity.com/vulnerabilityreport
form_platform: Bugcrowd
platforms:
- platform: Bugcrowd
programs:
- name: Comcast Xfinity Vulnerability Disclosure Program
url: https://bugcrowd.com/engagements/comcastvdp
status: 200
- name: Xfinity Home & xFi
url: https://bugcrowd.com/engagements/xfinity-home
status: 200
- name: Comcast MBB
url: https://bugcrowd.com/engagements/comcast-mbb
rewards:
offered: true
guaranteed: false
statement: >-
"not all submissions are eligible for a reward; eligibility depends on the
merit, quality, and impact of the findings."
scope_definition: >-
Comcast defines a security vulnerability as "an unintended weakness or
exposure that could be used to compromise the integrity, availability or
confidentiality of our products and services." Reports are accepted from
independent researchers, industry partners, vendors, customers and
consultants.
principles:
- Trust — confidentiality is maintained in exchanges with researchers.
- Respect — researchers are asked to avoid privacy violations, degradation of user experience, disruption of production systems and destruction of data.
- Transparency — researchers provide the technical detail needed to validate a report.
- Common Good — no public disclosure of unverified vulnerabilities before validation.
related:
research_program: https://corporate.comcast.com/cybersecurity/ccs-research
research_program_status: 200
covers_developer_platform: unknown
covers_developer_platform_note: >-
The policy is written for Comcast/Xfinity products and services generally. It
does not name the Firebolt developer platform, docs.developer.comcast.com or
the codebig2.net API hosts in scope, and the Bugcrowd scopes were not readable
anonymously. No claim is made either way.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/comcast-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.