generated: '2026-08-05' method: searched probe: true source: https://www.tigera.io/vulnerability-disclosure/ description: >- Tigera runs a published coordinated vulnerability-disclosure programme fronted by a PSIRT mailbox, with a public archive of numbered security bulletins (TTA-YYYY-NNN) going back to 2018. There is no bug-bounty programme and no RFC 9116 /.well-known/security.txt on any Tigera host — the policy is a web page only, so an automated agent following the security.txt convention will not find it. policy: - https://www.tigera.io/vulnerability-disclosure/ contact: - psirt@tigera.io scope: in_scope: - Project Calico (Calico Open Source) - Calico Enterprise - Calico Cloud out_of_scope: >- "Any service not explicitly mentioned above is excluded from this policy." submission: anonymous_accepted: true requested_details: - Description of the vulnerability - Steps to reproduce - Security risk assessment - Potential impact - Recommendations - Supporting technical details commitments: - Investigate the reported vulnerability - Respond with confirmation and a severity assessment - Develop a patch or workaround - Publicly announce the vulnerability where appropriate sla: published: false note: The policy states no numeric acknowledgement or remediation timeframe. bug_bounty: present: false platforms: [] advisories: url: https://www.tigera.io/security-bulletins/ scheme: TTA-YYYY-NNN published_bulletins: - TTA-2024-002 - TTA-2024-001 - TTA-2023-001 - TTA-2022-001 - TTA-2021-002 - TTA-2021-001 - TTA-2020-001 - TTA-2019-003 - TTA-2019-002 - TTA-2019-001 - TTA-2018-001 security_txt: present: false probed: - url: https://www.tigera.io/.well-known/security.txt status: 404 - url: https://docs.tigera.io/.well-known/security.txt status: 404 recommendation: >- Publishing an RFC 9116 security.txt on www.tigera.io with Contact: mailto:psirt@tigera.io and Policy: https://www.tigera.io/vulnerability-disclosure/ would make the existing programme machine-discoverable at zero cost. evidence: - source: https://www.tigera.io/vulnerability-disclosure/ kind: disclosure page status: 200 keywords: [vulnerability, security research, security issue, psirt] - source: https://www.tigera.io/security-bulletins/ kind: advisory archive status: 200 x-evidence: fetched: '2026-08-05'