Foreign Agricultural Service · Vulnerability Disclosure

Foreign Agricultural Service Vulnerability Disclosure

Vulnerability disclosure

Foreign Agricultural Service runs a coordinated vulnerability disclosure program on Bugcrowd.

AgricultureFederal GovernmentTradeOpen DataCommoditiesExportGovernment
Program: Bugcrowd

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-10'
method: searched
probe: true
source: https://bugcrowd.com/engagements/usda-vdp
note: >-
  FAS itself publishes no security or disclosure page. What covers it is the parent
  department's program: USDA runs a department-wide Vulnerability Disclosure Policy, operated
  as a Bugcrowd engagement. fas.usda.gov and apps.fas.usda.gov are usda.gov subdomains, so the
  agency inherits the department's policy the way a brand inherits its parent's — this is the
  same different-domain justification the pipeline accepts for a parent brand, stated
  explicitly rather than assumed.
program:
  type: vulnerability-disclosure-policy
  operator: Bugcrowd
  managed_by: U.S. Department of Agriculture
  bounty: false
  bounty_note: 'a VDP, not a paid bug bounty — Bugcrowd classifies the engagement as "Vulnerability Disclosure"'
policy:
  - https://www.usda.gov/vulnerability-disclosure-policy
  - https://bugcrowd.com/engagements/usda-vdp
contact: []
contact_note: >-
  Reports are submitted through the Bugcrowd engagement, not to an email address. No
  security@ address is published for FAS or for USDA, and no /.well-known/security.txt is
  served on any host — see well-known/foreign-agricultural-service-well-known.yml. The RFC
  9116 discovery path a scanner would look for does not exist, which is why this program is
  findable only by search.
evidence:
  - source: https://bugcrowd.com/engagements/usda-vdp
    kind: bug-bounty-platform-page
    http_status: 200
    fetched: '2026-09-10'
    detail: >-
      Live and public. Page title "Vulnerability Disclosure: United States Department of
      Agriculture: Vulnerability Disclosure Program"; og:title "United States Department of
      Agriculture: Vulnerability Disclosure Program | Bugcrowd"; og:description "Learn more
      about U.S. Federal Government's Vulnerability Disclosure engagement powered by
      Bugcrowd". Reached via a 301 from the older https://bugcrowd.com/usda-vdp path.
  - source: https://www.usda.gov/vulnerability-disclosure-policy
    kind: policy-page
    http_status: 403
    fetched: '2026-09-10'
    detail: >-
      NOT dead — an Akamai edge block on our crawler. The page returns the standard
      "Access Denied" edgesuite body for any request from this client, as does every other
      www.usda.gov path including the site root, while a browser-header request to the root
      succeeded once in the same session. The URL is the one USDA itself publishes as its VDP
      location. Recorded as live-but-unreadable rather than credited as read.
  - source: /.well-known/security.txt on www.fas.usda.gov and www.usda.gov
    kind: negative
    http_status: 404
    fetched: '2026-09-10'
    detail: real origin 404 on both hosts — no RFC 9116 file
scope:
  stated: USDA department-wide
  fas_assets_verified: false
  detail: >-
    The Bugcrowd brief carrying the in-scope asset list returned 301 to our fetcher and was
    not read, so it is NOT asserted here that fas.usda.gov or apps.fas.usda.gov appear on it
    by name. What is asserted is what is verifiable: USDA operates a department-wide VDP, and
    these are USDA hosts. A researcher should read the brief for the current asset list.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/foreign-agricultural-service-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.