generated: '2026-08-17' method: searched probe: true source: https://api.malt.com/.well-known/security.txt note: >- Malt runs a Coordinated Vulnerability Disclosure program on Yogosha, the French bug-bounty platform, and advertises it through an RFC 9116 security.txt served at api.malt.com. The automated probe (0-working/probe-security-programs.py) reported vdp=none because it probes www.malt.com, which answers 403 to non-browser clients behind Cloudflare; the document was found by probing the API host directly and is saved verbatim at well-known/malt-security.txt. policy: - https://app.yogosha.com/cvd/malt/rqtSc4eIMUj7CKFhA87hI contact: - https://app.yogosha.com/cvd/malt/rqtSc4eIMUj7CKFhA87hI program: kind: coordinated-vulnerability-disclosure platform: Yogosha url: https://app.yogosha.com/cvd/malt/rqtSc4eIMUj7CKFhA87hI http_status: 200 public_bounty: unknown note: >- The security.txt directs all vulnerability reports to the Yogosha CVD portal. Whether the program pays bounties, and its scope and safe-harbour terms, are not stated in the security.txt and are not published on a public page we could reach. preferred_languages: - en - fr security_txt: served_at: https://api.malt.com/.well-known/security.txt file: well-known/malt-security.txt expires: '2026-03-15T23:59:59Z' expired: true finding: >- security.txt Expires is 2026-03-15, already past at time of probe (2026-08-17). Per RFC 9116 the file should be treated as stale until refreshed. The VDP portal it points at is live (200). evidence: - source: https://api.malt.com/.well-known/security.txt kind: security.txt http_status: 200 content_type: text/plain fetched: '2026-08-17' - source: https://app.yogosha.com/cvd/malt/rqtSc4eIMUj7CKFhA87hI kind: vdp-portal http_status: 200 fetched: '2026-08-17' - source: well-known/malt-security.txt kind: harvested-artifact