How to report a vulnerability
Have you wondered where to report a vulnerability you have found? Do you want to report a vulnerability but cannot find any instructions? Have you heard that you can be paid for reporting vulnerabilities but do not know how the process works? We explain what you should do.
On this page
- What are vulnerabilities?
- What to do when you find a vulnerability
- How to find the right way to report a vulnerability
- What happens after you report a vulnerability?
- How can an organisation protect itself against vulnerabilities?
What are vulnerabilities?
A vulnerability is a weakness in an information system, application, device, process or way of working that can be exploited to cause harm. Vulnerabilities can exist, for example, in online services, home automation systems and organisations’ information systems. Human actions can also create vulnerabilities.
Vulnerabilities can be found in all types of technology. A vulnerability may be caused, for example, by a programming error, outdated technology or several weaknesses that are considered minor on their own but together create a more serious problem.
A vulnerability is usually made public only when its exploitation can be limited or an update is available to fix it.
What to do when you find a vulnerability
Stop testing once you have confirmed the vulnerability
Do not exploit the vulnerability unnecessarily. Stop testing as soon as you have been able to demonstrate that the vulnerability exists.
Do not disrupt the service, violate anyone’s privacy or alter, destroy, download or distribute data found in the service. Unauthorised handling of data may constitute a criminal offence.
Find out how the organisation accepts vulnerability reports
First, check whether the organisation has:
- contact details for reporting vulnerabilities
- a security.txt file
- responsible disclosure instructions
- a bug bounty programme
Follow the organisation’s reporting instructions.
Report the vulnerability securely
Describe the following as clearly as possible in your report:
- which service, product or system contains the vulnerability
- how the vulnerability can be verified
- what impact the vulnerability may have
- when you discovered the vulnerability
- how you can be contacted if necessary
Do not include unnecessary personal data, passwords or other sensitive information in your report. Do not publish details of the vulnerability before the organisation has had time to investigate and fix the problem.
Report the vulnerability to the NCSC-FI if necessary
You can report a vulnerability to the NCSC-FI if:
- you cannot find the organisation’s contact details or reporting instructions
- you do not know who you should send the report to
- the organisation does not respond to your report or responds negatively
- you want to remain anonymous
- you do not want to continue handling the matter yourself
The NCSC-FI will receive your report and, if necessary, help find the right contacts and coordinate the handling of the vulnerability.
How to find the right way to report a vulnerability
Choose how to report the vulnerability based on the instructions given by the organisation affected by it.
The organisation has a bug bounty programme
In a bug bounty programme, an organisation asks external parties to report vulnerabilities found in its products or services. If a report is accepted, the person who found the vulnerability may receive a reward, for example money.
Follow the programme rules, the permitted testing scope and the specified reporting channels. Also check what types of testing are allowed and what information you need to include in your report.
Some organisations run their own programmes. Others use bug bounty platforms such as HackerOne or Bugcrowd.
The organisation follows responsible disclosure principles
Responsible disclosure means that you report the vulnerability without delay through the channel specified by the organisation and keep the information confidential.
Stop testing once you have confirmed the vulnerability Do not disrupt the service, violate anyone’s privacy or alter or destroy any data you find.
Give the organisation a reasonable amount of time to investigate and fix the vulnerability before you publish information about it.
The organisation has its own reporting address
The organisation’s website may provide an email address or form for reporting vulnerabilities. Use this channel whenever possible and follow the organisation’s instructions.
The organisation may also ask you to send the report to the NCSC-FI.
If the organisation has a bug bounty programme but the case is handled through the NCSC-FI, the organisation running the bug bounty programme is responsible for paying any reward.
The organisation has a security.txt file
Security.txt is a file published on a website that provides contact details and instructions for reporting vulnerabilities.
You can look for the file by adding the following path to the website address:
/.well-known/security.txt
Example:
https://www.kyberturvallisuuskeskus.fi/.well-known/security.txt
On some websites, the file may also be available at:
/security.txt
The technical requirements for security.txt files are defined in RFC 9116.
What happens after you report a vulnerability?
The organisation will usually need to investigate the vulnerability, confirm it and assess its impact before it can fix the problem. Fixing the vulnerability may require software changes, testing, releasing an update and informing customers.
This means you may need to wait for a response or a fix. Give the organisation a reasonable amount of time to process your report. Avoid publishing details of the vulnerability while the matter is being handled.
If the organisation does not respond or the matter does not progress, you can contact the NCSC-FI.