Reporting a vulnerability
If you found a vulnerability, you can send it to [email protected]. Please follow the guidelines below while reporting it. Reports that ask for or demand a bounty before disclosure will not receive a reply. NL Times is a small organisation and as such we don't have an active bounty program.
What we would like to see from you
In order to help us triage submissions, we recommend that your report:
- Describes the location of the vulnerability that was discovered and the potential impact when exploited.
- Offer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful).
- Be in English or Dutch.
What you can expect from us
When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible.
- Within 3 business days, we will acknowledge that your report has been received.
- To the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution.
- We will maintain an open dialogue to discuss issues.
Location of our security.txt file: https://nltimes.nl/.well-known/security.txt