Skip to main content

New: Meet Apex, the agent that runs your security program while you sleep

Disclosures

Security disclosures

Vulnerabilities surfaced through the Cantina community and our research team — disclosed responsibly, coordinated with the affected vendor, and published once a fix is in reach.

cantina · disclosure

coordinating
  • Report received done
  • Triaged & validated done
  • Fix coordinated in progress
  • Advisory published queued

Every report is tracked from intake to public advisory.

Our policy

Coordinated disclosure, by default.

When our team or a member of the community finds a flaw in third-party software, the goal is a fix — not a headline. We report to the people who can patch it, hold the details until users are protected, then publish a clear advisory so everyone else can act.

The same principles apply to anything you report to us about Cantina. No legalese, no runaround — a direct line to the people who own the fix.

What we commit to

  • Good-faith research is welcome

    Report a suspected vulnerability in good faith and we will not pursue action against you for your research.

  • We coordinate before we publish

    Technical detail stays private while we work with the affected vendor toward a fix and a safe disclosure date.

  • Timelines are honest

    We align to a standard coordinated-disclosure window and adjust it openly with the vendor as remediation demands.

  • Researchers get credit

    Reporters are credited in the public advisory unless they ask to stay anonymous.

Our track record

Disclosed by the book — and in the open.

Everything our team and community surface runs the same coordinated path, then lands as a public advisory anyone can learn from.


CVE advisories & vulnerability write-ups
0 CVE advisories & vulnerability write-ups
Security research articles, all public
0+ Security research articles, all public
Standard coordinated-disclosure window
90-day Standard coordinated-disclosure window
Reports coordinated before we publish
0% Reports coordinated before we publish
How we work

We report to the people who can patch — not the press.

When our research team or the Cantina community proves a vulnerability, the work stays quiet. We take it straight to the vendor or maintainer, help drive the fix, and only go public once users are protected — then we credit the researcher who found it.


A fix, not a headline. Detail stays private until there's a patch to point to.

cantina · advisory fix shipped
Remote code execution in ActiveMQ Classic via an exposed Jolokia endpoint — coordinated with the maintainer, patched, then written up.
CVE-2026-34197 · RCE advisory published
The process

From report to public advisory.

Every disclosure runs the same path. You always know where a report stands and what happens next.

  1. 1

    Report

    You send us the details — affected component, versions, impact, and how to reproduce it. We acknowledge receipt and open a tracked case.

    typically same day

  2. 2

    Triage & validate

    We reproduce the issue, confirm severity, and map real-world impact. Duplicate or out-of-scope reports are closed with a clear explanation.

    days

  3. 3

    Coordinate the fix

    We work directly with the affected vendor or maintainer on a patch, request a CVE where warranted, and agree a disclosure date that protects users.

    vendor-led

  4. 4

    Public advisory

    Once a fix is available, we publish a clear write-up — root cause, impact, and remediation — and credit the reporter.

    after the fix

Recent advisories

Vulnerabilities we've disclosed

View all research
In the open

Security research, done in the open.

Every fix we coordinate becomes a public advisory — so the whole ecosystem gets to patch, not just the vendor we told first.

How to report

Send us what you found.

Reach the security team through our contact channel. A strong report is specific and reproducible — the more of the below you can include, the faster we can validate and act.

  • The affected component, product, or repository — and the exact versions.
  • A clear description of the vulnerability and its security impact.
  • Step-by-step reproduction, plus a proof-of-concept where you have one.
  • Any logs, configuration, or environment detail that helps us reproduce it.

Reporting in good faith? We won't pursue action against research conducted under this policy.

In scope

  • Third-party software our team or community is researching.
  • The Cantina platform, website, and supporting infrastructure.
  • Supply-chain issues in packages and dependencies we surface.

Out of scope

  • Reports without a realistic security impact or reproduction.
  • Volumetric DoS, social engineering, and physical attacks.
  • Findings that require a compromised device or privileged access you already hold.

Found something? Tell us.

Responsible disclosure keeps everyone safer. Send us a report and we'll take it from intake to coordinated fix — and credit your work.