Ginnie Mae · Vulnerability Disclosure

Ginnie Mae Vulnerability Disclosure

Vulnerability disclosure

Ginnie Mae runs a coordinated vulnerability disclosure program on Hackerone.

Federal GovernmentHousingMortgageMortgage-Backed SecuritiesOpen DataContentJSON:API
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-12'
method: searched
source: >-
  https://www.ginniemae.gov/site-policies/ginnie-mae-vulnerability-disclosure-policy
  (HTTP 200). The page is rendered client-side; its text was read through the site's
  own API at
  https://www.ginniemae.gov/api/v1/node/web_page/0a8f5c06-6e9f-4b49-a3a7-13c61fadd98a
  and the seven paragraph--accordion resources it references. Fetched 2026-09-12.
provider: Ginnie Mae
providerId: ginnie-mae
published: true
policy_url: https://www.ginniemae.gov/site-policies/ginnie-mae-vulnerability-disclosure-policy
program_type: coordinated-vulnerability-disclosure
shaped_by: CISA Binding Operational Directive 20-01
bug_bounty:
  offered: false
  detail: >-
    Explicitly not. The policy asks researchers not to request compensation for time,
    materials or vulnerabilities discovered. No HackerOne, Bugcrowd or Intigriti
    program was found.
reporting:
  channel: email
  address: ginniemaevdp@hud.gov
  anonymous_reports_accepted: true
  preferred_language: English
  requested_content:
    - Location of the vulnerability and the potential impact of exploitation
    - Detailed reproduction steps, with proof-of-concept scripts or screenshots
commitments:
  acknowledgement: 3 business days, when the researcher shares contact information
  coordination: >-
    Ginnie Mae commits to coordinating as openly and as quickly as possible, and will
    not share the reporter's name or contact information without express permission.
  onward_disclosure: >-
    Findings that affect all users of a product or service, not solely Ginnie Mae, may
    be shared with CISA and handled under its coordinated vulnerability disclosure
    process.
scope:
  in_scope:
    - '*.ginniemae.gov'
  out_of_scope:
    - Any connected service not expressly listed
    - Vulnerabilities in non-federal vendor systems, which go to the vendor's own policy
  note: >-
    Ginnie Mae states it will increase the scope of this policy over time, and invites
    researchers to ask at ginniemaevdp@hud.gov before testing anything they are unsure
    about, or to use the security contact in the .gov WHOIS record for the domain.
safe_harbour:
  present: true
  text_summary: >-
    "If you make a good faith effort to comply with this policy during your security
    research, we will consider your research to be authorized, we will work with you to
    understand and resolve the issue quickly, and Ginnie Mae will not recommend or
    pursue legal action related to your research."
authorized_activity:
  - Testing to detect a vulnerability or identify an indicator related to a vulnerability
  - Sharing with, or receiving from, Ginnie Mae information about a vulnerability
prohibited_test_methods:
  - Network denial of service (DoS/DDoS) or any test that impairs access to, or damages, a system or data
  - Physical testing, social engineering, phishing or vishing, and other non-technical testing
  - Full red-team penetration testing involving unauthorized access to servers
  - Social engineering or phishing of customers or employees
  - Theoretical vulnerabilities
  - Informational disclosure of non-sensitive data
  - Low-impact session management issues
  - Self XSS
researcher_obligations:
  - Notify the agency as soon as possible after discovering a real or potential issue
  - Avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data
  - Do no harm; do not exploit a vulnerability beyond the minimum needed to prove it exists
  - Do not intentionally access the content of communications, data or information beyond what is needed to prove the vulnerability
  - Do not exfiltrate data under any circumstances
  - Do not compromise the privacy or safety of Ginnie Mae personnel, contractors, affiliates or third parties
security_txt:
  published: false
  evidence: >-
    https://www.ginniemae.gov/.well-known/security.txt returns HTTP 200 with
    content-type text/html — the Angular application shell, not an RFC 9116 document.
    Probed 2026-09-12. This is the single cheapest improvement available to Ginnie Mae
    here: the policy, the contact address and the preferred language already exist and
    a security.txt would make them machine-discoverable at the location scanners
    actually look.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ginnie-mae-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.