Kroger · Vulnerability Disclosure
Kroger Vulnerability Disclosure
Vulnerability disclosure
Kroger runs a coordinated vulnerability disclosure program on Bugcrowd.
GroceriesGrocery RetailRetailE-CommerceProduct CatalogStore LocationsShopping CartLoyaltyAuthenticationPartner APIFortune 100
Program: Bugcrowd
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
specification: API Commons Vulnerability Disclosure
specificationVersion: '0.1'
provider: Kroger
providerId: kroger
generated: '2026-08-27'
method: probed
source: https://www.kroger.com/.well-known/security.txt
note: >-
Found by direct probe, not by the standard sweep: the repo's apis.yml host is
developer.kroger.com, whose SPA catch-all answers /.well-known/security.txt
with an HTML shell. The real RFC 9116 document is served from the corporate
host www.kroger.com and names a Bugcrowd-hosted disclosure program.
published: true
security_txt:
url: https://www.kroger.com/.well-known/security.txt
http_status: 200
canonical: https://www.kroger.com/.well-known/security.txt
contact: https://bugcrowd.com/kroger-vdp
preferred_languages: en
hiring: https://www.krogerfamilycareers.com/
policy: null
encryption: null
expires: null
file: ../well-known/kroger-security.txt
deviations:
- >-
No Expires field. RFC 9116 section 2.5.5 makes Expires REQUIRED; a
security.txt without it has no stated freshness.
- >-
No Policy field. The Contact URI resolves to the Bugcrowd engagement page,
which carries the policy, but security.txt does not point at it directly.
- >-
Served as content-type text/html rather than text/plain.
- >-
Not signed (no accompanying security.txt.sig).
program:
name: The Kroger Co - Vulnerability Disclosure Program
platform: Bugcrowd
url: https://bugcrowd.com/engagements/kroger-vdp
http_status: 200
type: vulnerability-disclosure
paid_bounty: unknown
note: >-
Program page resolves and is titled "The Kroger Co - Vulnerability
Disclosure Program". The engagement page renders its scope, safe-harbor and
response terms client-side; those specifics were not readable anonymously
and are deliberately not asserted here.
hosts_probed:
- host: www.kroger.com
path: /.well-known/security.txt
status: 200
- host: developer.kroger.com
path: /.well-known/security.txt
status: 200
result: html-shell (miss)
- host: api.kroger.com
path: /.well-known/security.txt
status: 404
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kroger-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.