generated: '2026-08-23' method: searched probe: true source: https://www.inrupt.com/security policy_url: https://www.inrupt.com/security advisories_url: https://www.inrupt.com/security/advisories contact: security@inrupt.com alternate_channel: https://inrupt.atlassian.net/servicedesk team: Inrupt Product Security Incident Response Team (PSIRT) bug_bounty: false bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti programme was found. Reporting is direct to PSIRT by email or Service Desk ticket; no bounty is offered. security_txt: false security_txt_note: >- No /.well-known/security.txt is served on www.inrupt.com, docs.inrupt.com or any ESS service host (all probed 2026-08-23, all 404). The disclosure policy exists but is not machine-discoverable at the RFC 9116 location. commitments: - Acknowledgement of report receipt - Communication of estimated time for resolution - Notification of fix out_of_scope_research: - Denial of Service (DoS) of any kind - Automated security tools - Accessing, or attempting to access, data that does not belong to you - Destroying or corrupting data that does not belong to you severity_scoring: framework: CVSS v3.1 reference: https://www.first.org/cvss/calculator/3.1 note: >- The stated internal scoring framework is CVSS v3.1, though the most recent published advisory (NRPT-2025-002) is scored with CVSS v4.0. third_party_cve_handling: >- Inrupt updates third-party components within regularly scheduled release cycles to the newest compatible version available during development, and states that a vulnerability in a third-party component does not necessarily translate to a vulnerability in Inrupt software. PSIRT accepts questions about the applicability of a third-party CVE. advisories: published: true count: 13 identifier_scheme: NRPT-YYYY-NNN contents: date, advisory ID, severity, CVSS vector, related CVE, summary, affected products recent: - id: NRPT-2025-002 date: '2025-08-08' title: ESS ingress-nginx Server-Snippet Vulnerability severity: CRITICAL cvss: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N (9.1)' related_cve: CVE-2021-25742 affected: ESS versions prior to 2.5.1 and 2.3.6 - id: NRPT-2025-001 date: '2025-06-30' title: Weak Password Derivation in Message Encryption - id: NRPT-2024-003 date: '2024-12-02' title: Authentication Token Exclusivity in ESS Endpoint Configuration - id: NRPT-2024-002 date: '2024-03-06' title: OpenID Token Manipulation Vulnerability in ESS Access Grant, Storage and Query Services - id: NRPT-2024-001 date: '2024-01-14' title: ESS Authorization Off-by-One Error in Shared Status Lists earliest: NRPT-2020-001 (2020-05-15, Authentication Token Capture-Replay) evidence: - source: https://www.inrupt.com/security kind: disclosure page http_status: 200 keywords: - vulnerability - PSIRT - security@inrupt.com - source: https://www.inrupt.com/security/advisories kind: advisory index http_status: 200 - source: https://www.inrupt.com/security/inrupt-security-public-asc kind: published PGP public key (listed in sitemap.xml)