Freddie Mac · Vulnerability Disclosure

Freddie Mac Vulnerability Disclosure

Vulnerability disclosure

Freddie Mac runs a coordinated vulnerability disclosure program on Bugcrowd. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Freddie MacHousingMortgageLendingServicingOriginationSecondary MarketMISMOFortune 100Government-Sponsored Enterprise
Program: Bugcrowd security.txt present

Disclosure Policy

Security Contact

Contact
mailto:freddie-mac@submit.bugcrowd.com
Contact
https://privacyportal.onetrust.com/incident-portal/webforms/94b5e41a-aba0-4e51-ba48-efa19ce560a1/1b25c37a-a280-44f2-b61e-a693a33c7267

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-10'
method: probed
probe: true
source: well-known/freddie-mac-api-security.txt
security_txt:
  url: https://api.freddiemac.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain
  fetched: '2026-09-10'
  mirror:
    url: https://api-test.freddiemac.com/.well-known/security.txt
    http_status: 200
    note: Byte-identical apart from its own Canonical line; the UAT gateway serves the same policy.
  fields_present:
  - Canonical
  - Contact
  - Expires
  - Preferred-Languages
  fields_absent:
  - Policy
  - Encryption
  - Acknowledgments
  - Hiring
  - CSAF
  expires: '2027-06-30'
  expires_valid: true
  note: RFC 9116 compliant and current. It is served ONLY from the two Apigee API gateway hosts. www.freddiemac.com,
    sf.freddiemac.com, mf.freddiemac.com, capitalmarkets.freddiemac.com and guide.freddiemac.com all 404
    on /.well-known/security.txt, and developer.freddiemac.com answers 401 on the whole /.well-known/
    space, so a researcher landing on any Freddie Mac property other than the API gateway finds nothing.
contact:
- mailto:freddie-mac@submit.bugcrowd.com
- https://privacyportal.onetrust.com/incident-portal/webforms/94b5e41a-aba0-4e51-ba48-efa19ce560a1/1b25c37a-a280-44f2-b61e-a693a33c7267
bug_bounty: true
bug_bounty_platform: Bugcrowd
bug_bounty_note: 'The Contact line routes submissions to freddie-mac@submit.bugcrowd.com, which is a Bugcrowd-managed
  intake address. There is no public program page: https://bugcrowd.com/freddie-mac returned 404 on 2026-09-10,
  so the engagement is private/invite-only rather than an open public bounty.'
policy_published: false
policy_note: 'No Policy: field is published, so a researcher is told where to send a report but not what
  scope, safe-harbour or response commitment applies.'
evidence:
- source: well-known/freddie-mac-api-security.txt
  kind: security.txt harvested verbatim 2026-09-10
  url: https://api.freddiemac.com/.well-known/security.txt
  http_status: 200
- url: https://bugcrowd.com/freddie-mac
  http_status: 404
  kind: no public Bugcrowd program page - the program is private
recommendation: 'Serve the same security.txt from www.freddiemac.com and sf.freddiemac.com, and add a
  Policy: line. Today the file only exists on the two hosts a researcher is least likely to browse to.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/freddie-mac-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.