generated: '2026-09-05' method: searched source: https://www.cloudfoundry.org/security/ program: exists: true type: coordinated-disclosure operator: Cloud Foundry Foundation Security Team (CFF Security Team) contact_email: security@cloudfoundry.org contact_page: https://www.cloudfoundry.org/security/ policy_page: https://www.cloudfoundry.org/security/ advisories: https://www.cloudfoundry.org/foundryblog/security-advisory/ bug_bounty: false bounty_platform: null scope: >- Undisclosed security vulnerabilities in open-source Cloud Foundry codebases. The Foundation states explicitly that ordinary bug reports and general security questions are NOT accepted at this address. encryption: pgp: true fingerprint: A576 4CD4 EE9A 002D 72F5 2A32 46B6 FF8F 8CF0 880C keyservers: - https://keys.openpgp.org - https://pgp.mit.edu process: >- Reporters are asked to notify the CFF Security Team privately before any public disclosure. Reports are triaged by CFF staff, volunteers, and vulnerability-management teams from participating member organizations; the Foundation states only organizations that demonstrate professionalism in handling inbound reports participate. Fixes are released and then announced as dated security advisories. security_txt: served: false probed: - url: https://www.cloudfoundry.org/.well-known/security.txt status: 404 - url: https://cloudfoundry.org/.well-known/security.txt status: 404 - url: https://docs.cloudfoundry.org/.well-known/security.txt status: 404 note: >- A real, well-run disclosure programme with no RFC 9116 security.txt. This is the single cheapest fix available to the Foundation — the Contact, Policy and Encryption values above are already published in prose on /security/ and would populate the file as-is. evidence: - url: https://www.cloudfoundry.org/security/ status: 200 found: reporting address, PGP fingerprint, disclosure process, advisories link - url: https://www.cloudfoundry.org/foundryblog/security-advisory/ status: 200 found: dated security advisory archive