Fannie Mae · Vulnerability Disclosure

Fannie Mae Vulnerability Disclosure

Vulnerability disclosure

Fannie Mae runs a coordinated vulnerability disclosure program on Hackerone.

Federal-GovernmentHousingMortgagesFinanceGSEFortune 100
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

fannie-mae-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-07'
method: searched
source: https://www.fanniemae.com/about-us/reporting-technology-vulnerability
note: >-
  Fannie Mae runs a first-party vulnerability disclosure channel — a published policy page and an
  intake form on its own domain. It does NOT run a bug bounty. The hackerone.com/fanniemae page that
  turns up in search is HackerOne's community-curated, explicitly UNCLAIMED directory entry (the page
  carries class "spec-external-unclaimed" and describes itself as "community-curated"); it is
  recorded here as a third-party listing, not as a Fannie Mae program.
program:
  exists: true
  type: vulnerability-disclosure-policy
  bug_bounty: false
  first_party: true
  policy_url: https://www.fanniemae.com/about-us/reporting-technology-vulnerability
  policy_status: 200
  submission_form: https://www.fanniemae.com/form/report-technology-vulnerability
  submission_form_status: 200
  security_txt: null
  security_txt_note: >-
    /.well-known/security.txt returns 404 on www.fanniemae.com, fanniemae.com and
    fmsso.fanniemae.com. The disclosure channel exists but is not machine-discoverable — publishing
    an RFC 9116 security.txt pointing at the existing form would close this with no new process.
  contact_email: iso_support@fanniemae.com
  contact_email_source: >-
    CAA iodef record on fanniemae.com — 128 iodef "mailto: iso_support@fanniemae.com" (see
    security/fannie-mae-domain-security.yml). This is the incident contact Fannie Mae publishes in DNS.
  submission_requirements:
    - Name, organization and contact information
    - Description of the vulnerability
    - Technical details
  stated_terms:
    - Reporters are instructed not to include nonpublic personal information (SSNs, financial account numbers) in a report.
    - Fannie Mae may share a report with law enforcement agencies or other industry participants.
    - Fannie Mae states it may not respond to the reporter or keep them apprised of the report's validity.
    - Vulnerabilities involving potential bodily harm should be reported to law enforcement immediately.
  safe_harbor: false
  safe_harbor_note: The policy page carries no explicit safe-harbor or researcher legal-protection language.
third_party_listings:
  - platform: HackerOne
    url: https://hackerone.com/fanniemae
    status: 200
    claimed_by_provider: false
    kind: community-curated directory entry
related:
  cybersecurity_requirements: https://www.fanniemae.com/about-us/corp-responsibility/governance/information-security-and-business-resiliency-supplement
  cybersecurity_requirements_status: 200
  cybersecurity_requirements_note: >-
    Requirements Fannie Mae imposes on its sellers, servicers and technology partners (including a
    36-hour cybersecurity incident notification obligation) — an obligation Fannie Mae places on
    others, not a certification Fannie Mae holds. It is deliberately NOT recorded as a trust center
    or compliance attestation.
trust_center:
  exists: false
  note: >-
    No trust center, no published SOC 2 / ISO 27001 / PCI / FedRAMP attestation, and no compliance
    portal was found on any fanniemae.com host (probe-security-programs.py 2026-09-07 returned
    vdp=none trust=none; this file is the manual upgrade of its vdp result). Fannie Mae is a
    government-sponsored enterprise supervised by FHFA; its published governance material is
    regulatory, not a customer-facing certification set.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fannie-mae-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.