Terms and policies

Learn more about Chainguard policies and our legal documents.

Coordinated Vulnerability Handling Policy

Last update: September 22, 2026

Purpose

The Chainguard Coordinated Vulnerability Disclosure Policy defines how Chainguard handles vulnerability coordination and disclosure when (1) Chainguard discovers non-public vulnerabilities in third-party projects and (2) embargoed vulnerabilities are reported to Chainguard from external third-parties. In all cases, Chainguard aims to share details publicly no later than ninety (90) calendar days from the notice date to minimize harm to the ecosystem.

Non-Public Vulnerability 

When Chainguard discovers a non-public vulnerability in third-party software, Chainguard immediately reports the vulnerability to the maintainer following the maintainer’s security policy and keeping the details private if possible.

  • Chainguard aims to share full details publicly ninety (90) calendar days from the notice date, or earlier if the maintainer releases a fix before that date.

  • If the maintainer notifies Chainguard that a fix is scheduled for release within fourteen (14) calendar days after the ninety (90) calendar day deadline, disclosure will be delayed until the fix is available. If the fix is not published within those fourteen (14) calendar days, disclosure proceeds unless extreme circumstances apply.

  • Chainguard may publish on the regular schedule listed above (90 days from the notice date) without feedback from the maintainer.

Embargoed Vulnerability 

Embargoed Vulnerabilities are a subset of non-public vulnerabilities where there is a specific, agreed-upon restriction on disclosure. Reporters, Chainguard, and upstream maintainers should agree on a reasonable timeline to resolve the issue before public disclosure. Unless we determine a compelling security-related reason otherwise, we aim to share details publicly after ninety (90) calendar days from the date the vulnerability is reported.

We commit to:

  • Timely initial response and active communication throughout the coordination process;

  • Remediation of confirmed vulnerabilities with commercially reasonable efforts, or in accordance with our CVE SLA, as applicable;

  • Implementing industry-standard mechanisms for the secure transmission, storage, and access of Embargoed Vulnerability information; and

  • Transparency when further embargoed coordination is required to effectively deliver a fix.

Shortened Disclosure Timelines

In all cases, Chainguard reserves the right to shorten the public disclosure timelines above if a vulnerability is discovered to be under active exploitation (a “0-day”), details are already publicly known through other channels, in other exceptional situations (e.g., a new class of vulnerabilities requiring extraordinary coordination, e.g. with Meltdown/Spectre), or as required under applicable law. In any case, we will notify the reporter of any changes to the disclosure timeline and continue to coordinate throughout the process to reduce harm.

CVE Assignment

Chainguard is a CVE Numbering Authority (CNA) and assigns CVE IDs in accordance with CNA rules, and as agreed to by its Root. Which party assigns the CVE ID for a given vulnerability depends on whether an upstream maintainer or a more specific CNA is in a position to assign it:

  • Software Chainguard develops, maintains or distributes - Chainguard assigns the CVE ID for vulnerabilities introduced by Chainguard's own packaging or patching of the software it distributes. An upstream flaw in software that Chaingaurd packages but does not maintain is not within this scope

  • Third-party projects with their own assignment authority - Where the affected project is itself a CNA, or falls within the scope of a CNA that covers it, Chainguard acts as a reporter and does not assign. The CVE ID is assigned by that CNA or its Root.

  • Third-party projects without their own assignment authority and/or no longer maintained - Chainguard assigns the CVE ID for vulnerabilities in open source projects processed through Athena, where upstream has remediated without an identifier being assigned, or where no maintainer is active, and no other specific CNA covers the project.

  • At disclosure, Chainguard publishes a CVE record and a corresponding public advisory, in coordination with the upstream maintainer and the reporter where applicable. Where Chainguard assigns the CVE ID for a project it does not maintain, Chainguard notifies that project's maintainer before the record is published. Where a CVE ID is assigned by another party after Chainguard has already published an advisory, Chainguard adds that identifier to the existing advisory record. CVE records published by Chainguard describe the upstream software. They carry the affected and fixed version ranges, severity, weakness classification and references, and do not include Chainguard-specific remediation details.

Contacting Us

This policy is primarily designed to minimize harm to downstream users and upstream maintainers, both in its application on the micro-scale, for individual disclosures, and the macro-scale, across all disclosures. We believe this policy does so, while also respecting the needs of both maintainers and researchers. If you have any questions, please contact us at:

Version260522

If you entered into an Order prior to September 22, 2026, you can find your applicable terms here-https://www.chainguard.dev/legal/coordinated-vulnerability-handling-policy-260522

Version241924

If you entered into an Order prior to May 22, 2026, you can find your applicable terms here-

https://www.chainguard.dev/legal/outbound-vulnerability-disclosure-policy-241924