U.S. Department of Transportation · Vulnerability Disclosure

Us Dot Vulnerability Disclosure

Vulnerability disclosure

U.S. Department of Transportation runs a coordinated vulnerability disclosure program on Bugcrowd.

TravelUnited StatesAviationAirlinesAirportsGovernmentRegulatorDistributionAviation Consumer ProtectionOpen DataTransportationSafetyStatisticsAutomotiveRail
Program: Bugcrowd

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: >-
  https://www.faa.gov/web_policies/vulnerability_disclosure_policy (fetched verbatim
  2026-07-28), https://www.transportation.gov/vulnerability-disclosure-policy (Akamai
  403 to every automated client; text read from the Internet Archive snapshot
  20260727163352), https://bugcrowd.com/engagements/usdot-vdp (HTTP 200 2026-07-28)
summary: >-
  U.S. DOT runs TWO coordinated vulnerability disclosure programs, both public, both
  with explicit safe-harbour authorisation, and neither discoverable by machine. The
  departmental VDP is operated on Bugcrowd; the FAA runs its own separate program by
  email. Automated discovery fails completely: no host in the department publishes an
  RFC 9116 /.well-known/security.txt (every probe 404, and the departmental web tier
  403s automated clients outright), so a scanner sees nothing while two fully staffed
  programs are running.
programs:
- name: U.S. DOT Vulnerability Disclosure Policy
  operator: U.S. Department of Transportation, Office of the Chief Information Officer
  policy_url: https://www.transportation.gov/vulnerability-disclosure-policy
  policy_url_alt: https://www.dot.gov/vulnerability-disclosure-policy
  submission_url: https://bugcrowd.com/engagements/usdot-vdp
  platform: Bugcrowd
  contact: DOT-VDP@dot.gov
  bounty: false
  bounty_note: >-
    "DOT does not provide payment for vulnerability submissions and, by submitting a
    vulnerability report, you acknowledge that you have no expectation of payment and
    that you expressly waive any future payment claims against the U.S. Government
    related to your submission. Additionally, DOT will not provide any type of
    recognition for disclosed vulnerabilities." (verbatim)
  safe_harbor: true
  safe_harbor_text: >-
    "If you make a good faith effort to comply with this policy during your security
    research, we will consider your research to be authorized. We will work with you to
    understand and resolve the issue quickly, and DOT will not recommend or pursue legal
    action related to your research. Should legal action be initiated by a third party
    against you for activities that were conducted in accordance with this policy, we
    will make this authorization known." (verbatim)
  coordination: Cybersecurity and Infrastructure Security Agency (CISA)
  scope_domains:
  - 911.gov
  - bts.gov
  - cmts.gov
  - distracteddriving.gov
  - distraction.gov
  - dot.gov
  - ems.gov
  - flyhealthy.gov
  - nhtsa.gov
  - nhtsa.dot.gov
  - protectyourmove.gov
  - safecar.gov
  - safercar.gov
  - safertruck.gov
  - safeocs.gov
  - trafficsafetymarketing.gov
  - transportation.gov
  - usmma.edu
  scope_note: >-
    Subdomains included. Explicitly excluded: FAA-operated sites (they carry their own
    VDP link), and any site DOT does not directly manage. "Any services not explicitly
    identified here are considered out-of-scope and are not authorized for testing."
  relevance_to_apis: >-
    data.transportation.gov, datahub.transportation.gov and data.bts.gov fall inside
    transportation.gov / bts.gov and are therefore in scope. The FAA API gateway hosts
    (external-api.faa.gov, external.apic4e.faa.gov, api.faa.gov) are NOT — they belong to
    the FAA program below.
- name: FAA Vulnerability Disclosure Policy
  operator: Federal Aviation Administration
  policy_url: https://www.faa.gov/web_policies/vulnerability_disclosure_policy
  policy_date: '2023-01-26'
  submission_url: null
  platform: email
  contact: vulnerabilitydisclosure@faa.gov
  bounty: false
  bounty_note: >-
    "the FAA does not provide payment for vulnerability submissions ... Additionally the
    FAA will not provide any type of recognition for disclosed vulnerabilities." (verbatim)
  safe_harbor: true
  safe_harbor_text: >-
    "If you make a good faith effort to comply with this policy during your security
    research, the FAA will consider your research to be authorized, work with you to
    understand and resolve the issue quickly, and will not recommend or pursue legal
    action related to your research conducted pursuant to this policy." (verbatim)
  disclosure_embargo_days: 90
  disclosure_embargo_text: >-
    "The FAA requires that reporters of vulnerabilities refrain from public disclosure
    for a minimum of 90 calendar days from the date the FAA acknowledges receipt of the
    report."
  acknowledgement_sla: 3 business days when contact information is shared
  anonymous_reports_accepted: true
  coordination: [CISA, Transportation Security Administration (TSA), affected vendors and open source projects]
  scope_note: >-
    "This policy applies to all public-facing FAA systems and services." That covers
    every FAA API host in this repo — external-api.faa.gov, external.apic4e.faa.gov,
    api.faa.gov, catalog.data.faa.gov. Researchers unsure whether a system is in scope
    are told to email vulnerabilitydisclosure@faa.gov before starting.
  prohibited_methods:
  - Testing systems outside the declared scope
  - Physical testing of facilities
  - Social engineering / phishing of FAA users
  - Denial of Service or Resource Exhaustion attacks
  - Introducing malicious software
  - Testing third-party applications that integrate with FAA systems
  - Deleting, altering, sharing, retaining or destroying FAA data
  - Exfiltrating data, establishing command line access or persistence, or pivoting
security_txt:
  published: false
  probes:
  - {host: external-api.faa.gov, path: /.well-known/security.txt, status: 404}
  - {host: external.apic4e.faa.gov, path: /.well-known/security.txt, status: 404}
  - {host: www.faa.gov, path: /.well-known/security.txt, status: 404}
  - {host: catalog.data.faa.gov, path: /.well-known/security.txt, status: 404}
  - {host: data.transportation.gov, path: /.well-known/security.txt, status: 404}
  - {host: datahub.transportation.gov, path: /.well-known/security.txt, status: 404}
  - {host: data.bts.gov, path: /.well-known/security.txt, status: 404}
  - {host: www.transportation.gov, path: /.well-known/security.txt, status: 403, note: Akamai bot block; cannot be confirmed either way}
  - {host: www.bts.gov, path: /.well-known/security.txt, status: 403, note: Akamai bot block}
  - {host: api.faa.gov, path: /.well-known/security.txt, status: 200, note: FALSE POSITIVE — Gravitee portal serves its Angular index.html for every unmatched path}
  finding: >-
    Both programs would be trivially machine-discoverable with a nine-line security.txt
    on each host. Neither publishes one. This is the single cheapest fix available to
    the department.
evidence:
- source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy
  kind: disclosure-policy-page
  status: 200
  verified: '2026-07-28'
  note: Fetched with a browser User-Agent; the FAA web tier serves automated clients normally.
- source: https://bugcrowd.com/engagements/usdot-vdp
  kind: bug-bounty-platform-engagement
  status: 200
  verified: '2026-07-28'
- source: https://www.transportation.gov/vulnerability-disclosure-policy
  kind: disclosure-policy-page
  status: 403
  verified: '2026-07-28'
  note: >-
    Live host returns Akamai "Access Denied" to every non-browser client including a
    spoofed Chrome User-Agent. Content read from the Internet Archive capture
    web.archive.org/web/20260727163352/ and cross-checked against the search index.