U.S. Department of Transportation · Vulnerability Disclosure
Us Dot Vulnerability Disclosure
Vulnerability disclosure
U.S. Department of Transportation runs a coordinated vulnerability disclosure program on Bugcrowd.
TravelUnited StatesAviationAirlinesAirportsGovernmentRegulatorDistributionAviation Consumer ProtectionOpen DataTransportationSafetyStatisticsAutomotiveRail
Program: Bugcrowd
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-07-28'
method: searched
probe: true
source: >-
https://www.faa.gov/web_policies/vulnerability_disclosure_policy (fetched verbatim
2026-07-28), https://www.transportation.gov/vulnerability-disclosure-policy (Akamai
403 to every automated client; text read from the Internet Archive snapshot
20260727163352), https://bugcrowd.com/engagements/usdot-vdp (HTTP 200 2026-07-28)
summary: >-
U.S. DOT runs TWO coordinated vulnerability disclosure programs, both public, both
with explicit safe-harbour authorisation, and neither discoverable by machine. The
departmental VDP is operated on Bugcrowd; the FAA runs its own separate program by
email. Automated discovery fails completely: no host in the department publishes an
RFC 9116 /.well-known/security.txt (every probe 404, and the departmental web tier
403s automated clients outright), so a scanner sees nothing while two fully staffed
programs are running.
programs:
- name: U.S. DOT Vulnerability Disclosure Policy
operator: U.S. Department of Transportation, Office of the Chief Information Officer
policy_url: https://www.transportation.gov/vulnerability-disclosure-policy
policy_url_alt: https://www.dot.gov/vulnerability-disclosure-policy
submission_url: https://bugcrowd.com/engagements/usdot-vdp
platform: Bugcrowd
contact: DOT-VDP@dot.gov
bounty: false
bounty_note: >-
"DOT does not provide payment for vulnerability submissions and, by submitting a
vulnerability report, you acknowledge that you have no expectation of payment and
that you expressly waive any future payment claims against the U.S. Government
related to your submission. Additionally, DOT will not provide any type of
recognition for disclosed vulnerabilities." (verbatim)
safe_harbor: true
safe_harbor_text: >-
"If you make a good faith effort to comply with this policy during your security
research, we will consider your research to be authorized. We will work with you to
understand and resolve the issue quickly, and DOT will not recommend or pursue legal
action related to your research. Should legal action be initiated by a third party
against you for activities that were conducted in accordance with this policy, we
will make this authorization known." (verbatim)
coordination: Cybersecurity and Infrastructure Security Agency (CISA)
scope_domains:
- 911.gov
- bts.gov
- cmts.gov
- distracteddriving.gov
- distraction.gov
- dot.gov
- ems.gov
- flyhealthy.gov
- nhtsa.gov
- nhtsa.dot.gov
- protectyourmove.gov
- safecar.gov
- safercar.gov
- safertruck.gov
- safeocs.gov
- trafficsafetymarketing.gov
- transportation.gov
- usmma.edu
scope_note: >-
Subdomains included. Explicitly excluded: FAA-operated sites (they carry their own
VDP link), and any site DOT does not directly manage. "Any services not explicitly
identified here are considered out-of-scope and are not authorized for testing."
relevance_to_apis: >-
data.transportation.gov, datahub.transportation.gov and data.bts.gov fall inside
transportation.gov / bts.gov and are therefore in scope. The FAA API gateway hosts
(external-api.faa.gov, external.apic4e.faa.gov, api.faa.gov) are NOT — they belong to
the FAA program below.
- name: FAA Vulnerability Disclosure Policy
operator: Federal Aviation Administration
policy_url: https://www.faa.gov/web_policies/vulnerability_disclosure_policy
policy_date: '2023-01-26'
submission_url: null
platform: email
contact: vulnerabilitydisclosure@faa.gov
bounty: false
bounty_note: >-
"the FAA does not provide payment for vulnerability submissions ... Additionally the
FAA will not provide any type of recognition for disclosed vulnerabilities." (verbatim)
safe_harbor: true
safe_harbor_text: >-
"If you make a good faith effort to comply with this policy during your security
research, the FAA will consider your research to be authorized, work with you to
understand and resolve the issue quickly, and will not recommend or pursue legal
action related to your research conducted pursuant to this policy." (verbatim)
disclosure_embargo_days: 90
disclosure_embargo_text: >-
"The FAA requires that reporters of vulnerabilities refrain from public disclosure
for a minimum of 90 calendar days from the date the FAA acknowledges receipt of the
report."
acknowledgement_sla: 3 business days when contact information is shared
anonymous_reports_accepted: true
coordination: [CISA, Transportation Security Administration (TSA), affected vendors and open source projects]
scope_note: >-
"This policy applies to all public-facing FAA systems and services." That covers
every FAA API host in this repo — external-api.faa.gov, external.apic4e.faa.gov,
api.faa.gov, catalog.data.faa.gov. Researchers unsure whether a system is in scope
are told to email vulnerabilitydisclosure@faa.gov before starting.
prohibited_methods:
- Testing systems outside the declared scope
- Physical testing of facilities
- Social engineering / phishing of FAA users
- Denial of Service or Resource Exhaustion attacks
- Introducing malicious software
- Testing third-party applications that integrate with FAA systems
- Deleting, altering, sharing, retaining or destroying FAA data
- Exfiltrating data, establishing command line access or persistence, or pivoting
security_txt:
published: false
probes:
- {host: external-api.faa.gov, path: /.well-known/security.txt, status: 404}
- {host: external.apic4e.faa.gov, path: /.well-known/security.txt, status: 404}
- {host: www.faa.gov, path: /.well-known/security.txt, status: 404}
- {host: catalog.data.faa.gov, path: /.well-known/security.txt, status: 404}
- {host: data.transportation.gov, path: /.well-known/security.txt, status: 404}
- {host: datahub.transportation.gov, path: /.well-known/security.txt, status: 404}
- {host: data.bts.gov, path: /.well-known/security.txt, status: 404}
- {host: www.transportation.gov, path: /.well-known/security.txt, status: 403, note: Akamai bot block; cannot be confirmed either way}
- {host: www.bts.gov, path: /.well-known/security.txt, status: 403, note: Akamai bot block}
- {host: api.faa.gov, path: /.well-known/security.txt, status: 200, note: FALSE POSITIVE — Gravitee portal serves its Angular index.html for every unmatched path}
finding: >-
Both programs would be trivially machine-discoverable with a nine-line security.txt
on each host. Neither publishes one. This is the single cheapest fix available to
the department.
evidence:
- source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy
kind: disclosure-policy-page
status: 200
verified: '2026-07-28'
note: Fetched with a browser User-Agent; the FAA web tier serves automated clients normally.
- source: https://bugcrowd.com/engagements/usdot-vdp
kind: bug-bounty-platform-engagement
status: 200
verified: '2026-07-28'
- source: https://www.transportation.gov/vulnerability-disclosure-policy
kind: disclosure-policy-page
status: 403
verified: '2026-07-28'
note: >-
Live host returns Akamai "Access Denied" to every non-browser client including a
spoofed Chrome User-Agent. Content read from the Internet Archive capture
web.archive.org/web/20260727163352/ and cross-checked against the search index.