Coordinated Vulnerability Disclosure Policy
Purpose
Kravex conducts independent security research to improve the safety of software and the people who rely on it. We believe that responsible reporting of vulnerabilities, paired with timely public disclosure, protects users and advances the field. This policy sets out how Kravex discloses vulnerabilities it discovers in third-party software and services. It is our standing framework and applies to all Kravex research disclosures unless a separate agreement (for example, a client engagement contract) governs the work.
Scope
This policy covers vulnerabilities Kravex discovers through its own independent research. It does not govern findings produced during paid client engagements, which are confidential to the client and handled under the relevant contract and non-disclosure agreement.
Default process (coordinated disclosure)
- Private report. We report the vulnerability confidentially to the vendor best positioned to remediate it (the "vendor"), providing a clear description, affected versions, an impact assessment, and a proof of concept sufficient to reproduce the issue.
- Acknowledgement. We ask the vendor to acknowledge receipt within 14 days.
- Reminders. We send a reminder on day 15 and a final notice on day 30 restating the disclosure timeline and the intended publication date.
- Coordination window. Our standard coordination window is 45 days from the initial private report. We expect the vendor to develop and ship a fix within this window. At the end of the window we publish an advisory containing a description, a risk and impact assessment, mitigation guidance, the CVE identifier, and enough technical detail to demonstrate the issue.
- Good-faith extensions. If the vendor is making consistent, demonstrable progress but cannot ship within 45 days, we may agree a reasonable extension by mutual consent.
- CVE assignment. Where the vendor is a CVE Numbering Authority (CNA), or is covered by one (for example, through GitHub Security Advisories), we coordinate CVE assignment with them. Where the vendor is not a CVE partner, Kravex reserves a CVE identifier itself through the CVE Numbering Authority of Last Resort (MITRE).
Non-responsive vendors
If a vendor does not acknowledge our report within 30 days, we treat them as non-responsive. At that point Kravex will publish the vulnerability details — description, risk and impact, mitigation, and demonstrative technical detail — and will obtain a CVE identifier itself. We will not allow an unresponsive vendor to delay disclosure indefinitely.
Fixes, silent patches, and unattributed CVEs
- If a fix is made generally available at any time — through an official patch or a silent patch — Kravex may publish its advisory immediately, regardless of any remaining coordination window, because a public fix removes the user-safety rationale for withholding details.
- If a vendor remediates the issue but does not request or assign a CVE identifier, Kravex will obtain a CVE itself — from the vendor's CNA where possible, and otherwise from MITRE as the CNA of Last Resort — so that the issue is properly catalogued and the research is credited. A silent or unattributed patch will not deprive a finding of a CVE, nor Kravex of attribution.
Active exploitation
Where Kravex observes a vulnerability being actively exploited, the priority is to enable defenders to act. In such cases we aim to notify the vendor and publish essential risk information within approximately 72 hours of discovery, regardless of whether a fix is available, and we will, where feasible, notify directly affected parties we are aware of first.
Cloud and hosted services
Where a vulnerability affects a hosted service that only the vendor can remediate (users have nothing to patch on their end), Kravex does not reserve a CVE identifier. If the issue is resolved within the coordination window we will assess the value of public disclosure; if it remains unresolved after the window closes, we may disclose in line with the default process.
Good faith
Kravex research is conducted in good faith. We do not access, modify, or destroy data beyond what is necessary to demonstrate a vulnerability; we do not degrade services; and we interact only with systems and accounts we are authorised to test or that fall within legitimate, lawful research. We ask vendors to treat good-faith research accordingly and not to pursue legal action against researchers acting under this policy.
Discretion
Vulnerabilities can involve undefined behaviour and unexpected interactions. Kravex may adjust any timeline in this policy at its sole discretion where circumstances reasonably require it (for example, unusually complex remediation or acute user-safety considerations).
Publication and contact
Kravex advisories are published at kravex.ro, alongside the associated CVE record. To report a vulnerability to Kravex, or to discuss an ongoing disclosure, contact contact@kravex.ro