generated: '2026-07-25' method: searched probe: true source: https://www.3gpp.org/delegates-corner/coordinated-vulnerability-disclosure program: Coordinated Vulnerability Disclosure (CVD) policy: - https://www.3gpp.org/delegates-corner/coordinated-vulnerability-disclosure contact: [] submission: online form on the CVD page scope: >- Suspected or proven vulnerabilities caused by errors, omissions or ambiguities in 3GPP Technical Specifications, particularly those that could compromise components of 3GPP networks, terminal equipment connected to them, or interworking networks and equipment. The programme covers the standards themselves, not any 3GPP operated service, and is run in conjunction with other Standards Development Organizations. bug_bounty: false security_txt: false evidence: - source: https://www.3gpp.org/delegates-corner/coordinated-vulnerability-disclosure kind: disclosure page title: 'Coordinated Vulnerability Disclosure: 3GPP' quote: >- In conjunction with other Standards Development Organizations and related bodies, 3GPP has put in place a mechanism by which individuals or organizations can notify us of suspected or proven vulnerability caused by errors, omissions or ambiguities in our Technical Specifications. notes: - >- The automated probe first matched https://www.3gpp.org/security/responsible-disclosure, which is a soft 404 (the CMS serves the home page for unknown paths). That false positive was replaced with the real programme page found in the site navigation. - No /.well-known/security.txt is published on any 3GPP host; see well-known/3gpp-well-known.yml.