Skip to content

Rules Change Request: Mandatory minimum good-faith safe harbor commitment in CNA disclosure policies #52

Description

@boblord

Rules Change Request: Mandatory minimum good-faith safe harbor commitment in CNA disclosure policies

Section affected: 3.2.6 (CVE ID Assignment and Vulnerability Disclosure), specifically 3.2.6.1 through 3.2.6.3

Current text:

3.2.6 The CVE Program itself does not follow or require a specific Vulnerability disclosure policy. CNAs and other CVE Program participants operate under a variety of Vulnerability disclosure policies.

3.2.6.3 CNAs MAY require CVE ID assignment to be made using specific processes or mechanisms. Such processes or mechanisms MUST NOT conflict with the CNA Operational Rules.

Problem: 3.2.6.1 and 3.2.6.2 require every CNA to publish guidance on how it assigns CVE IDs within the context of Vulnerability disclosure, and to provide a URL to that policy. Nothing requires the content of that policy to protect a good-faith researcher who reports a vulnerability. Legal exposure, response time, and embargo handling for a reporter are entirely CNA-dependent, and 3.2.6 states plainly that the Program itself doesn't follow or require a specific disclosure policy, leaving no floor.

This is not a hypothetical gap. Genuine safe harbor commitments remain the exception rather than the norm even among large, well-resourced organizations with no shortage of legal sophistication to draft one. disclose.io's public directory at state.disclose.io, built on the open, CC0-licensed diodb directory, grades disclosure programs and policies against its open-source diostatus maturity model, and lets anyone check a given organization's status directly. Voluntary discretion has had a long runway, more than seven years since disclose.io's 2018 launch, and adoption has plateaued well short of universal, which is precisely the condition under which a rules-level floor becomes necessary rather than aspirational.

Proposed change: Add 3.2.6.6:

A CNA's published Vulnerability disclosure policy MUST include, at minimum, the following commitments to a good-faith Vulnerability reporter: (1) an authorization of good-faith security research consistent with the CNA's published reporting process, together with a waiver of the CNA's own legal claims, including under computer-crime, anti-circumvention, and terms-of-service laws or their non-US equivalents, arising from research activity that falls within that authorization; (2) a defined maximum response time within which the CNA MUST acknowledge receipt of a report; (3) a defined maximum embargo period after which the CNA MUST either publish a CVE Record or provide the reporter a documented, substantive justification for continued non-disclosure; and (4) a public escalation path the reporter MAY use if the CNA becomes unresponsive, consistent with 4.6. A CNA satisfies clause (1) by adopting an open, community-maintained safe harbor template, such as the disclose.io Safe Harbor terms, or terms substantially similar to such a template, rather than drafting bespoke legal language.

Amend 3.2.6.3 to read:

CNAs MAY require CVE ID assignment to be made using specific processes or mechanisms. Such processes or mechanisms MUST NOT conflict with the CNA Operational Rules, and MUST NOT conflict with the minimum good-faith reporter protections required under 3.2.6.6.

Rationale: Gives every good-faith reporter a uniform baseline of protection instead of one that depends entirely on which CNA they happen to be dealing with. Ties the Program's existing publication requirement (3.2.6.1, 3.2.6.2) to substantive minimum content rather than leaving the content entirely to each CNA's discretion.

Clause (1) is framed as authorization plus waiver rather than a blanket prohibition on legal action, because a CNA cannot categorically promise not to pursue legal action for conduct outside the scope of good-faith research it has actually authorized, and counsel reviewing a bare "MUST NOT pursue legal action" commitment would reasonably read it as an uncontrolled rights waiver. The authorization-plus-waiver construction is the version that survives legal review in practice; it has direct lineage to the safe harbor language most modern vulnerability disclosure programs use, tracing back to Dropbox's 2018 safe harbor commitment, and is the same construction standardized in the open-licensed disclose.io terms. Permitting compliance via an existing open template, rather than requiring each CNA's counsel to draft bespoke language from scratch, turns adoption from a legal-drafting burden into a low-effort copy-paste, which is more likely to produce actual uniform protection than a rule that leaves every CNA solving the same problem independently.

The rule deliberately does not have the Program specify fixed numeric values for the response-time or embargo maximums in clauses (2) and (3), leaving each CNA to publish its own, consistent with the existing structure of these rules, which generally sets requirements rather than specific durations. If a fixed anchor is wanted for reference, ISO/IEC 29147 and the CERT/CC 45-day disclosure norm are established points of comparison. A defined maximum embargo is also not purely aspirational: mechanisms already exist, such as timelock encryption that enforces publication at a deadline independent of the discloser's cooperation, that make an embargo commitment enforceable as a mechanism rather than a promise, which is the direction the ecosystem is already moving regardless of what the CNA Operational Rules require.

Activity

  1. JonathanLEvans commented on Jul 22, 2026

    @JonathanLEvans

    (3) a defined maximum embargo period after which the CNA MUST either publish a CVE Record or provide the reporter a documented, substantive justification for continued non-disclosure

    This would be a drastic departure for how the MITRE CNE-LR has operated. At minimum, it would change the timing of when people request CVEs from MITRE. Also, MITRE does not currently have a method for publishing vulnerabilities that complies with the CNA rules.

  2. zmanion commented on Jul 28, 2026

    @zmanion
    Collaborator

    I'm very much in favor of CVD and safe harbor. I'm also pretty firmly against the CVE Program getting into CVD policy. Clearly when and how CVE IDs are assigned is within Program scope. What happens in CVD (often leading up to CVE ID assignment) is out of scope and gets complicated pretty quickly (consider national reporting regulations and bug bounty terms and conditions).

    That said, I could maybe live with a SHOULD in the proposed 3.2.6.6 text. I appreciate that the CVE Program (including the CNA Rules) could be a positive influence on CVD policy and safe harbor.

  3. added
    4.4.0Candidates for 4.4.0
    and removed
    4.3.0Candidates for 4.3.0
    on Sep 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    4.4.0Candidates for 4.4.0

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions