RFC 9116: A File Format to Aid in Security Vulnerability Disclosure
In plain English — editorial summary, not part of the RFC
When security vulnerabilities are discovered by researchers, proper reporting channels are often lacking. As a result, vulnerabilities may be left unreported. This document defines a machine-parsable format ("security.txt") to help organizations describe their vulnerability disclosure practices to make it easier for researchers to report vulnerabilities.
Document record
- Document ID
- RFC9116
- Published
- April 2022
- Authors
- E. Foudil; Y. Shafranovich
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- —
- Pages
- 21
- Also known as
- —
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?