Vulnerability Disclosure Policy

As a global leader in media as well as SaaS for publishing, The Washington Post embraces responsible software development norms. To support a healthy internet ecology, we are sharing our Vulnerability Disclosure Policy. This policy describes the submission process for security researchers wanting to share their findings with our engineering teams.

Vulnerability Disclosure Policy

TL;DR

  • The Washington Post is publishing its Vulnerability Disclosure Policy to encourage responsible disclosure of security findings.
  • The policy outlines commitments to researchers, including confidentiality and timely remediation of serious issues.
  • Researchers are requested to maintain confidentiality, provide detailed reproduction steps, and avoid out-of-scope testing.
  • Out-of-scope activities include physical security testing, social engineering, DoS/DDoS attacks, and testing third-party SaaS apps.
  • In-scope examples include various web vulnerabilities such as BOLAs/IDORs, OWASP API Top 10, and authentication flaws.