generated: '2026-09-06' method: searched source: >- https://www.hud.gov/vulnerability-disclosure-policy (HTTP 200, fetched 2026-09-06). The reporting address was recovered by decoding the page's Cloudflare data-cfemail attributes, which the site uses to obfuscate it. provider: Department of Housing and Urban Development providerId: department-of-housing-and-urban-development program: published: true type: vulnerability disclosure policy (no bug bounty) name: HUD Vulnerability Disclosure Policy document: HUD Handbook 2400.45 REV 2.0 effective: '2023-06-21' url: https://www.hud.gov/vulnerability-disclosure-policy authority: >- Published under CISA Binding Operational Directive 20-01, which requires every US federal civilian executive branch agency to operate a VDP. rescinds: Revision 1.0 of the HUD Vulnerability Disclosure Policy reporting: method: email contact: VDP@hud.gov scope_question_contact: VDP@hud.gov requested_report_contents: - Uniform Resource Locator (URL) - Type of issue - Product version and configuration of software concerned template: 'Appendix A: Vulnerability Disclosure Template (in the policy document)' commitments: acknowledgement: within 3 business days investigation: >- HUD OCIO investigates every disclosure and keeps the researcher informed as remediation proceeds. researcher_recognition: >- HUD states it wants researchers to be recognized publicly for their contributions where the researcher wishes it. coordinated_disclosure: >- HUD works with researchers to set a reasonable period between report and public disclosure. safe_harbor: offered: true text: >- "If you make a good faith effort to comply with this policy during your security research, HUD will consider your research to be authorized, will work with you to understand, and resolve the issue quickly, and will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, HUD will make this authorization known." scope: covered: All HUD systems and services, per section 4 of the policy. excluded: - >- Vulnerabilities in systems supplied by HUD vendors — report those to the vendor under the vendor's own disclosure policy. - >- HUD employees and contractors with network access, who follow the HUD Departmental Rules of Behavior instead. bug_bounty: offered: false platform: null note: >- No HackerOne, Bugcrowd or Intigriti program was found for HUD. Reporting is direct to VDP@hud.gov. security_txt: served: false note: >- /.well-known/security.txt returns 404 on every HUD host, and https://www.hud.gov/security.txt returns 200 with Content-Length: 0 — an empty file. The policy and the contact both exist; only the RFC 9116 machine-readable pointer to them is missing. Publishing a security.txt with Policy: https://www.hud.gov/vulnerability-disclosure-policy and Contact: mailto:VDP@hud.gov would close this with no new commitment. see: well-known/department-of-housing-and-urban-development-well-known.yml