Kroger · Vulnerability Disclosure

Kroger Vulnerability Disclosure

Vulnerability disclosure

Kroger runs a coordinated vulnerability disclosure program on Bugcrowd.

GroceriesGrocery RetailRetailE-CommerceProduct CatalogStore LocationsShopping CartLoyaltyAuthenticationPartner APIFortune 100
Program: Bugcrowd

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

kroger-vulnerability-disclosure.yml Raw ↑
specification: API Commons Vulnerability Disclosure
specificationVersion: '0.1'
provider: Kroger
providerId: kroger
generated: '2026-08-27'
method: probed
source: https://www.kroger.com/.well-known/security.txt
note: >-
  Found by direct probe, not by the standard sweep: the repo's apis.yml host is
  developer.kroger.com, whose SPA catch-all answers /.well-known/security.txt
  with an HTML shell. The real RFC 9116 document is served from the corporate
  host www.kroger.com and names a Bugcrowd-hosted disclosure program.
published: true
security_txt:
  url: https://www.kroger.com/.well-known/security.txt
  http_status: 200
  canonical: https://www.kroger.com/.well-known/security.txt
  contact: https://bugcrowd.com/kroger-vdp
  preferred_languages: en
  hiring: https://www.krogerfamilycareers.com/
  policy: null
  encryption: null
  expires: null
  file: ../well-known/kroger-security.txt
  deviations:
    - >-
      No Expires field. RFC 9116 section 2.5.5 makes Expires REQUIRED; a
      security.txt without it has no stated freshness.
    - >-
      No Policy field. The Contact URI resolves to the Bugcrowd engagement page,
      which carries the policy, but security.txt does not point at it directly.
    - >-
      Served as content-type text/html rather than text/plain.
    - >-
      Not signed (no accompanying security.txt.sig).
program:
  name: The Kroger Co - Vulnerability Disclosure Program
  platform: Bugcrowd
  url: https://bugcrowd.com/engagements/kroger-vdp
  http_status: 200
  type: vulnerability-disclosure
  paid_bounty: unknown
  note: >-
    Program page resolves and is titled "The Kroger Co - Vulnerability
    Disclosure Program". The engagement page renders its scope, safe-harbor and
    response terms client-side; those specifics were not readable anonymously
    and are deliberately not asserted here.
hosts_probed:
  - host: www.kroger.com
    path: /.well-known/security.txt
    status: 200
  - host: developer.kroger.com
    path: /.well-known/security.txt
    status: 200
    result: html-shell (miss)
  - host: api.kroger.com
    path: /.well-known/security.txt
    status: 404
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kroger-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.