Tigera · Vulnerability Disclosure

Tigera Vulnerability Disclosure

Vulnerability disclosure

Tigera runs a published coordinated vulnerability-disclosure programme fronted by a PSIRT mailbox, with a public archive of numbered security bulletins (TTA-YYYY-NNN) going back to 2018. There is no bug-bounty programme and no RFC 9116 /.well-known/security.txt on any Tigera host — the policy is a web page only, so an automated agent following the security.txt convention will not find it.

Tigera publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyKubernetesNetworkingNetwork SecurityContainer SecurityCloud NativeObservabilityMicrosegmentationZero TrusteBPFOpen Source
Program:

Disclosure Policy

Policy

Security Contact

Contact
psirt@tigera.io

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://www.tigera.io/vulnerability-disclosure/
description: >-
  Tigera runs a published coordinated vulnerability-disclosure programme fronted by a PSIRT
  mailbox, with a public archive of numbered security bulletins (TTA-YYYY-NNN) going back to
  2018. There is no bug-bounty programme and no RFC 9116 /.well-known/security.txt on any Tigera
  host — the policy is a web page only, so an automated agent following the security.txt
  convention will not find it.
policy:
- https://www.tigera.io/vulnerability-disclosure/
contact:
- psirt@tigera.io
scope:
  in_scope:
  - Project Calico (Calico Open Source)
  - Calico Enterprise
  - Calico Cloud
  out_of_scope: >-
    "Any service not explicitly mentioned above is excluded from this policy."
submission:
  anonymous_accepted: true
  requested_details:
  - Description of the vulnerability
  - Steps to reproduce
  - Security risk assessment
  - Potential impact
  - Recommendations
  - Supporting technical details
commitments:
- Investigate the reported vulnerability
- Respond with confirmation and a severity assessment
- Develop a patch or workaround
- Publicly announce the vulnerability where appropriate
sla:
  published: false
  note: The policy states no numeric acknowledgement or remediation timeframe.
bug_bounty:
  present: false
  platforms: []
advisories:
  url: https://www.tigera.io/security-bulletins/
  scheme: TTA-YYYY-NNN
  published_bulletins:
  - TTA-2024-002
  - TTA-2024-001
  - TTA-2023-001
  - TTA-2022-001
  - TTA-2021-002
  - TTA-2021-001
  - TTA-2020-001
  - TTA-2019-003
  - TTA-2019-002
  - TTA-2019-001
  - TTA-2018-001
security_txt:
  present: false
  probed:
  - url: https://www.tigera.io/.well-known/security.txt
    status: 404
  - url: https://docs.tigera.io/.well-known/security.txt
    status: 404
  recommendation: >-
    Publishing an RFC 9116 security.txt on www.tigera.io with Contact: mailto:psirt@tigera.io
    and Policy: https://www.tigera.io/vulnerability-disclosure/ would make the existing
    programme machine-discoverable at zero cost.
evidence:
- source: https://www.tigera.io/vulnerability-disclosure/
  kind: disclosure page
  status: 200
  keywords: [vulnerability, security research, security issue, psirt]
- source: https://www.tigera.io/security-bulletins/
  kind: advisory archive
  status: 200
x-evidence:
  fetched: '2026-08-05'