Envoy Gateway · Vulnerability Disclosure
Envoy Gateway Vulnerability Disclosure
Vulnerability disclosure
Envoy Gateway runs a real coordinated-disclosure programme with a named private mailbox, a stated response target, a stated maximum embargo, CVE assignment, and a documented set of announcement channels. It is written down in the repository, not implied. probe-security-programs.py found nothing because the project publishes no /.well-known/security.txt and no bug-bounty platform page — the policy lives in SECURITY.md, which the automated probe does not read.
Envoy Gateway runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
API GatewayCNCFEnvoyKubernetesOpen-SourceGateway APIIngressService MeshCloud NativegRPC
Program: Hackerone
Disclosure Policy
Policy
Policy
Policy
Policy
Policy
Security Contact
Contact
emailenvoy-gateway-security@googlegroups.com
Contact
methodprivate email to the security team
Contact
publicIssuesProhibitedtrue
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.