generated: '2026-08-02' method: searched probe: true source: https://www.solo.io/security policy: - https://www.solo.io/security contact: - security@solo.io bug_bounty: none published security_txt: none security_txt_note: /.well-known/security.txt returns 404 on solo.io, www.solo.io, and docs.solo.io program: reporting: >- "Send an email to the private security@solo.io mailing list with the vulnerability details." acknowledgement: The security team acknowledges and analyzes reports within three working days. confidentiality: Vulnerability information shared with the team remains private and is not disseminated to other projects. remediation: Fixes are developed in a private GitHub repository to prevent premature disclosure. disclosure: >- Announcements are made simultaneously across the Solo.io blog, X/Twitter, Slack (#general), and customer support channels. in_scope: - Potential vulnerabilities in Solo.io products or projects - Uncertainty about whether an issue is a vulnerability or what its impact is - Vulnerabilities in dependencies such as Envoy, Docker, Istio, and Kubernetes evidence: - source: https://www.solo.io/security kind: disclosure page keywords: - vulnerability - security research - report a security - security issue - security@ - source: https://www.solo.io/security kind: security contact value: security@solo.io x-evidence: fetched: '2026-08-02' url: https://www.solo.io/security http_status: 200