Vulnerability Disclosure
Vulnerability Disclosure Policy
Blaze supports coordinated vulnerability disclosure. This policy explains how to report a security issue affecting Blaze and how we coordinate disclosure when our researchers find vulnerabilities in third-party products.
Report a vulnerability affecting Blaze
Email [email protected] with the subject “Vulnerability disclosure”. For sensitive findings, ask us for a suitable secure channel before sending technical details or evidence. Include the affected Blaze-operated website or service, a description of the issue and potential impact, clear steps to reproduce it, minimal evidence, and a way to contact you if you want a response. Include relevant dates or prerequisites when useful. Remove passwords, access tokens, and unrelated personal data. Do not publish sensitive findings in a public GitHub issue.
Scope and responsible testing
Reports about systems operated by Blaze are welcome. Client systems and third-party services are outside this policy, even when Blaze has assessed or linked to them. Reporting a vulnerability does not itself authorize testing. If you are uncertain about ownership, scope, or permission, contact us before proceeding.
Keep any testing within the authorization you have. Avoid disruption, denial of service, social engineering, persistence, changes to data, lateral movement, and access to other people's accounts. Use the minimum evidence needed to demonstrate the issue. If you encounter personal data, credentials, or other sensitive information, stop further access and report the exposure without copying or retaining more than necessary.
What happens after a report
We review the information, assess whether it affects Blaze, and may ask for clarification or additional reproduction details. Where an issue is confirmed, we assess its impact and the appropriate remediation. If you provide contact details, we aim to keep you informed of relevant progress. The time needed depends on the issue, its complexity, and any third parties involved.
Please coordinate public disclosure with us so we can address the issue and reduce risk to affected people. This policy does not offer a bug bounty or guarantee a reward. It cannot authorize testing of systems owned by others.
Vulnerabilities Blaze finds in third-party products
Our researchers seek an appropriate security contact for the vendor or maintainer and share enough information to reproduce and assess the issue, using a suitable secure channel where available. If the initial report receives no response, we normally follow up after seven days and try other appropriate contact channels. We may seek help from a coordination body such as CERT/CC when direct coordination is unsuccessful or several parties are affected. An email that does not bounce is not proof that the report reached the right team.
Disclosure timing
Our usual target is coordinated disclosure approximately 45 days after the initial private report to the vendor. We may extend that period, commonly up to 90 days, when the vendor is making meaningful progress and additional time is justified. Timing depends on severity, evidence of exploitation, available mitigations, and the work needed to release and deploy a fix. Active exploitation may justify earlier disclosure; complex remediation may justify a longer period.
If a vendor does not respond or a fix is unavailable by the agreed date, we assess whether publication will help users protect themselves and what information can be released without unnecessary risk. Where practicable, we notify the vendor of the intended publication date beforehand. Publication is not automatic on a fixed day.
Advisories and technical detail
An advisory may describe affected versions, impact, remediation or workarounds, the disclosure timeline, and research credits. We include technical detail or proof-of-concept material when it helps users and maintainers understand or verify the issue, while considering misuse risk. We do not publish confidential client information or unnecessary personal data. Findings from client engagements remain subject to applicable confidentiality and disclosure terms.
Historical advisories and Blaze's original 2016 policy: https://github.com/blazeinfosec/advisories. This page is our current policy for new reports and coordination.
Last updated: 28 September 2026.