Skip to main content
XOR
[DISCLOSURE]

Coordinated disclosure

Our researchers find vulnerabilities in the software we build environments from. We report each one to the people who can fix it, and we say nothing else about it until there is a fix to point at.

[PENDING]

We have requested CVE identifiers for the findings behind the Unpatched benchmark, and we are waiting on MITRE. Nothing has been assigned yet.

Reporting something to us

If you have found a vulnerability in something XOR runs, tell us through the contact form and we will reply with a way to send the details safely. We will not publish your report before you are ready.