Liberty Global · Vulnerability Disclosure

Liberty Global Vulnerability Disclosure

Vulnerability disclosure

Liberty Global runs a coordinated vulnerability disclosure program on Hackerone.

TelecommunicationsUnited KingdomBroadbandFixed BroadbandMobile Network OperatorNetwork APIsCAMARAOpen Gateway5GEuropeSet-Top BoxRDK
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
published: false
summary: >-
  Liberty Global publishes no vulnerability disclosure policy. No security.txt,
  no responsible-disclosure page, no security contact address, no bug bounty
  programme it operates. The only artifact that exists is an unclaimed
  third-party directory entry on HackerOne, recorded below because it is easily
  mistaken for a programme. No `Security` pointer is wired into apis.yml —
  there is no policy URL to point at.
policy: []
contact: []
security_txt:
  published: false
  note: >-
    /.well-known/security.txt and /security.txt both return 404 on
    www.libertyglobal.com, the only first-party host that resolves. See
    well-known/liberty-global-well-known.yml.
external_listing:
  platform: HackerOne
  url: https://hackerone.com/libertyglobal
  program_id: 5947
  program_name: Liberty Global Ventures
  is_external_program: true
  claimed: false
  offers_rewards: false
  policy: null
  policy_url: null
  disclosure_email: ''
  disclosure_url: ''
  scopes: [libertyglobal.com, liberty.com]
  fetched: '2026-07-25'
  http_status: 200
  assessment: >-
    This is a HackerOne *external* directory record, not a Liberty Global
    programme. HackerOne's own JSON marks it is_external_program: true and
    claimed: false, with a null policy, an empty disclosure email and an empty
    disclosure URL. Nobody at Liberty Global has claimed it and there is no
    published brief a researcher could follow. It is a listing, not a front
    door — and it is named after Liberty Global Ventures, the investment arm,
    not the operating group. Recorded as evidence, not counted as a disclosure
    programme.
probed:
- {url: 'https://www.libertyglobal.com/.well-known/security.txt', status: 404}
- {url: 'https://www.libertyglobal.com/security.txt', status: 404}
- {url: 'https://www.libertyglobal.com/security/', status: 404}
- {url: 'https://www.libertyglobal.com/responsible-disclosure/', status: 404}
- {url: 'https://www.libertyglobal.com/vulnerability-disclosure/', status: 404}
- {url: 'https://www.libertyglobal.com/report-a-vulnerability/', status: 404}
- {url: 'https://www.libertyglobal.com/about/corporate-governance/responsible-disclosure/', status: 404}
- {url: 'https://bugcrowd.com/libertyglobal', status: 404}
- {url: 'https://security.libertyglobal.com', status: DNS NXDOMAIN}
- {url: 'https://trust.libertyglobal.com', status: DNS NXDOMAIN}
adjacent_evidence:
- source: https://www.libertyglobal.com/about/corporate-governance/data-privacy-protection/
  kind: corporate-security-governance-page
  fetched: '2026-07-25'
  http_status: 200
  detail: >-
    Names GDPR, the Sarbanes-Oxley Act, ISO 27001, CAS(T) and PCI DSS, and
    describes a "Digital Confidence" team overseeing privacy, lawful intercept
    and security. It does not reference a vulnerability disclosure process or
    publish a security contact. Captured in
    conformance/liberty-global-conformance.yml.
- source: https://www.libertyglobal.com/careers/vacancy/business-information-security-officer-req_00037975/
  kind: job-posting
  fetched: '2026-07-25'
  detail: >-
    A live Business Information Security Officer vacancy, and a cybersecurity
    graduate scheme, confirm a real internal security function exists. It has
    no public reporting channel.
note_for_researchers: >-
  A researcher who finds a flaw in a Liberty Global property has no documented
  route to report it to the parent. The practical channels are the operating
  companies' own programmes (Virgin Media O2, VodafoneZiggo, Telenet) or the
  developers@libertyglobal.com address advertised on the LibertyGlobal GitHub
  organisation profile — which sits alongside a blog URL,
  https://developer.libertyglobal.com, that is NXDOMAIN, so its liveness is
  unverified.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/liberty-global-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.