generated: '2026-08-04' method: searched probe: true source: https://hubble.com/docs/security/sdk/vulnerability-handling policy: - https://hubble.com/docs/security/sdk/vulnerability-handling contact: - security@hubble.com bug_bounty: program: false platform: null note: No HackerOne, Bugcrowd or Intigriti program found; disclosure is direct-to-email. security_txt: published: false path: /.well-known/security.txt status: 404 note: RFC 9116 security.txt is NOT served on hubble.com, api.hubble.com, dash.hubble.com or network.hubble.com — the policy exists only in the developer docs. process: psirt: true embargo: acknowledge_and_analyze: 1 week fix: 30 days downstream_distribution: 60 days maximum_embargo: 90 days advisories: Kept confidential to the PSIRT, the reporter, and parties Hubble approves, until embargo expiry. cve: Associated CVEs and documentation are updated when the embargo ends. public_page: https://hubble.com/docs/security/sdk/vulnerabilities evidence: - source: https://hubble.com/docs/security/sdk/vulnerability-handling kind: disclosure-policy http_status: 200 fetched: '2026-08-04' - source: https://hubble.com/docs/security/sdk/vulnerabilities kind: advisory-index fetched: '2026-08-04' - source: https://hubble.com/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-08-04'