Tendermint · Vulnerability Disclosure

Tendermint Vulnerability Disclosure

Vulnerability disclosure

Tendermint runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyInfrastructureBlockchainConsensusCosmosWeb3JSON-RPCNode
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://hackerone.com/cosmos

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-21'
method: searched
probe: false
source: https://github.com/tendermint/tendermint/blob/main/SECURITY.md
policy:
  - https://hackerone.com/cosmos
  - https://github.com/tendermint/tendermint/blob/main/SECURITY.md
contact:
  - https://hackerone.com/cosmos
bug_bounty:
  platform: HackerOne
  url: https://hackerone.com/cosmos
  scope: Cosmos SDK, Tendermint Core, Gaia and related components
disclosure_process: >-
  Coordinated disclosure managed through the HackerOne bug bounty program.
  Reporters submit privately via HackerOne rather than public channels. Process
  covers CVSS severity assessment, private patch preparation for eligible
  releases, CVE request, 24h+ community pre-notification before release, public
  fix, downstream notification, security advisory publication, bounty payout,
  and a detailed vulnerability post ~7 days after release.
evidence:
  - source: https://github.com/tendermint/tendermint/blob/main/SECURITY.md
    kind: security-policy
  - source: https://hackerone.com/cosmos
    kind: bug-bounty