Ginnie Mae · Vulnerability Disclosure
Ginnie Mae Vulnerability Disclosure
Vulnerability disclosure
Ginnie Mae runs a coordinated vulnerability disclosure program on Hackerone.
Federal GovernmentHousingMortgageMortgage-Backed SecuritiesOpen DataContentJSON:API
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-12'
method: searched
source: >-
https://www.ginniemae.gov/site-policies/ginnie-mae-vulnerability-disclosure-policy
(HTTP 200). The page is rendered client-side; its text was read through the site's
own API at
https://www.ginniemae.gov/api/v1/node/web_page/0a8f5c06-6e9f-4b49-a3a7-13c61fadd98a
and the seven paragraph--accordion resources it references. Fetched 2026-09-12.
provider: Ginnie Mae
providerId: ginnie-mae
published: true
policy_url: https://www.ginniemae.gov/site-policies/ginnie-mae-vulnerability-disclosure-policy
program_type: coordinated-vulnerability-disclosure
shaped_by: CISA Binding Operational Directive 20-01
bug_bounty:
offered: false
detail: >-
Explicitly not. The policy asks researchers not to request compensation for time,
materials or vulnerabilities discovered. No HackerOne, Bugcrowd or Intigriti
program was found.
reporting:
channel: email
address: ginniemaevdp@hud.gov
anonymous_reports_accepted: true
preferred_language: English
requested_content:
- Location of the vulnerability and the potential impact of exploitation
- Detailed reproduction steps, with proof-of-concept scripts or screenshots
commitments:
acknowledgement: 3 business days, when the researcher shares contact information
coordination: >-
Ginnie Mae commits to coordinating as openly and as quickly as possible, and will
not share the reporter's name or contact information without express permission.
onward_disclosure: >-
Findings that affect all users of a product or service, not solely Ginnie Mae, may
be shared with CISA and handled under its coordinated vulnerability disclosure
process.
scope:
in_scope:
- '*.ginniemae.gov'
out_of_scope:
- Any connected service not expressly listed
- Vulnerabilities in non-federal vendor systems, which go to the vendor's own policy
note: >-
Ginnie Mae states it will increase the scope of this policy over time, and invites
researchers to ask at ginniemaevdp@hud.gov before testing anything they are unsure
about, or to use the security contact in the .gov WHOIS record for the domain.
safe_harbour:
present: true
text_summary: >-
"If you make a good faith effort to comply with this policy during your security
research, we will consider your research to be authorized, we will work with you to
understand and resolve the issue quickly, and Ginnie Mae will not recommend or
pursue legal action related to your research."
authorized_activity:
- Testing to detect a vulnerability or identify an indicator related to a vulnerability
- Sharing with, or receiving from, Ginnie Mae information about a vulnerability
prohibited_test_methods:
- Network denial of service (DoS/DDoS) or any test that impairs access to, or damages, a system or data
- Physical testing, social engineering, phishing or vishing, and other non-technical testing
- Full red-team penetration testing involving unauthorized access to servers
- Social engineering or phishing of customers or employees
- Theoretical vulnerabilities
- Informational disclosure of non-sensitive data
- Low-impact session management issues
- Self XSS
researcher_obligations:
- Notify the agency as soon as possible after discovering a real or potential issue
- Avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data
- Do no harm; do not exploit a vulnerability beyond the minimum needed to prove it exists
- Do not intentionally access the content of communications, data or information beyond what is needed to prove the vulnerability
- Do not exfiltrate data under any circumstances
- Do not compromise the privacy or safety of Ginnie Mae personnel, contractors, affiliates or third parties
security_txt:
published: false
evidence: >-
https://www.ginniemae.gov/.well-known/security.txt returns HTTP 200 with
content-type text/html — the Angular application shell, not an RFC 9116 document.
Probed 2026-09-12. This is the single cheapest improvement available to Ginnie Mae
here: the policy, the contact address and the preferred language already exist and
a security.txt would make them machine-discoverable at the location scanners
actually look.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ginnie-mae-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.