generated: '2026-08-26' method: searched source: https://www.nuna.com/report-an-issue/ name: Nuna Vulnerability Disclosure program: published: true type: coordinated-disclosure bug_bounty: false platform: null policy_url: https://www.nuna.com/report-an-issue/ contact: mailto:vulnerabilities@nuna.com contact_email: vulnerabilities@nuna.com intake: email scope: stated: Nuna's website, applications, and services note: >- The page does not enumerate in-scope hosts, out-of-scope classes, safe-harbor language, a response SLA, or a reward structure. submission_requirements: - description of the vulnerability - impact on Nuna applications and services - reproduction steps - any other information needed to replicate and fix the issue response_commitment: >- "Once we have a chance to triage the issue, someone from our Security team will follow up regarding the status of the reported vulnerability." No timeframe is stated. gaps: - id: no-security-txt detail: >- https://www.nuna.com/.well-known/security.txt returns 404, so an automated scanner or agent cannot discover this program. Publishing an RFC 9116 security.txt pointing Policy: and Contact: at this page would make it machine-discoverable. - id: no-safe-harbor detail: The policy states no safe-harbor / legal-protection commitment for good-faith researchers. x-evidence: - url: https://www.nuna.com/report-an-issue/ http_status: 200 fetched: '2026-08-26' note: >- Returns 403 to a non-browser User-Agent (Cloudflare/WP Engine WAF); 200 with a normal browser User-Agent. The page is live — the 403 is an edge policy, not a dead page. - url: https://www.nuna.com/.well-known/security.txt http_status: 404 fetched: '2026-08-26'