generated: '2026-09-05' method: searched source: https://ubuntu.com/security/disclosure-policy provider: Canonical providerId: canonical description: 'Canonical publishes a named, dated vulnerability disclosure and embargo policy covering Ubuntu, Canonical-authored software (LXD, MAAS, Juju, snapd, Snapcraft, Landscape, Launchpad, Mir) and Canonical-owned and -managed infrastructure. It is one of the more complete disclosure programs in the catalog: it names the reporting channels, publishes a PGP key for encrypted submissions, and states the embargo expectations on both sides.' program: published: true url: https://ubuntu.com/security/disclosure-policy http_status: 200 probed: '2026-09-05' valid_since: 2020-10 last_updated: 2023-10 owner: Ubuntu Security Team, Canonical scope: '"Canonical''s Ubuntu Security Team tends to the security needs of the Ubuntu operating system and serves as a point of contact for Canonical-authored software, both proprietary and open-source, as well as Canonical-owned and -managed infrastructure."' posture: responsible / coordinated disclosure contacts: - channel: email value: security@ubuntu.com note: Primary reporting address named in the policy. - channel: email value: security@canonical.com note: Contact published in the security.txt served at landscape.canonical.com. - channel: bug tracker value: https://launchpad.net/ note: Reports may be filed through the Launchpad bug reporting interface (or `ubuntu-bug `). Canonical warns in the policy that Launchpad sends plaintext email in response. encryption: pgp_key_id: 75E1 451E 529B 51E1 9006 CD5E 91EC 85F1 DA9A 776D keyserver: https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x75e1451e529b51e19006cd5e91ec85f1da9a776d note: Reports may optionally be encrypted to this OpenPGP key. security_txt: served: true hosts: - host: landscape.canonical.com url: https://landscape.canonical.com/.well-known/security.txt http_status: 200 file: ../well-known/canonical-security.txt fields: Contact: mailto:security@canonical.com Expires: '2024-01-01T02:59:00.000Z' Hiring: https://canonical.com/careers/all?search=Security gap: THE ONE REAL DEFECT HERE. The security.txt is EXPIRED — its own Expires field reads 2024-01-01, more than two and a half years before this probe — and it is served on exactly one host (landscape.canonical.com). canonical.com, ubuntu.com, snapcraft.io, charmhub.io, launchpad.net and every API host returned 404 for /.well-known/security.txt on 2026-09-05. A company that runs a mature disclosure program is not advertising it at the machine-readable path an automated scanner looks at. Refreshing Expires and serving the file from canonical.com and ubuntu.com would be a small change with disproportionate effect. bug_bounty: published: false note: No paid bounty program was found. The disclosure policy does not mention a bounty, and platform probes on 2026-09-05 did not confirm one. probes: - url: https://hackerone.com/canonical status: 404 - url: https://bugcrowd.com/canonical status: 404 - url: https://hackerone.com/ubuntu status: 200 note: 200 but the body is a 2.3KB SPA shell with a generic HackerOne and no program content, so it does not confirm a program exists. advisories: ubuntu_security_notices: url: https://ubuntu.com/security/notices machine_readable: https://ubuntu.com/security/notices.json api: canonical:ubuntu-security-api note: Canonical publishes its advisory stream as a real, open, unauthenticated API — USNs and CVEs queryable as JSON, with an OpenAPI (Swagger 2.0) at https://ubuntu.com/security/api/spec.json. Very few providers in the catalog publish their own vulnerability feed as a contract. cve_tracker: https://ubuntu.com/security/cves