# What is Coordinated Vulnerability Disclosure (CVD)?

> Coordinated vulnerability disclosure (CVD) is a process in which a vulnerability reporter, affected supplier or maintainer, deployers, coordinators, and other relevant parties exchange information so a weakness can be validated, addressed, and communicated with reduced avoidable harm.

- Canonical URL: https://yellowcube.eu/glossary/coordinated-vulnerability-disclosure/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Coordination covers reporting, analysis, remediation or mitigation, publication, and updates; it is a risk-reduction process, not a promise of secrecy or supplier control over disclosure.

The participants, products, jurisdictions, and urgency vary between cases. Clear reporting channels, acknowledgment, secure information handling, status communication, escalation paths, and criteria for public disclosure help the parties work despite incomplete evidence or competing responsibilities.

### Key points

- **Intake and validation:** Capture reproducible evidence without requesting unnecessary sensitive data, acknowledge receipt, establish a secure contact path, assess affected versions and impact, and identify other affected parties.
- **Coordination work:** Share enough information for analysis, remediation, mitigation, testing, and downstream preparation; agree on roles and target dates where possible, and revisit the plan when risk or progress changes.
- **Public communication:** Advisories should help users identify affected products and take protective action, credit contributors where agreed, distinguish fixes from workarounds, and provide durable references and updates.
- **Important limitation:** CVD cannot guarantee a fix, consensus, confidentiality, or a particular timeline. A disclosure policy or safe-harbor statement applies only as written and within its scope and jurisdiction; it is not universal immunity from legal or third-party claims.

### Related terms

[Vulnerability](<https://yellowcube.eu/glossary/vulnerability/>) · [Common Vulnerabilities and Exposures (CVE)](<https://yellowcube.eu/glossary/common-vulnerabilities-and-exposures/>) · [Vulnerability management](<https://yellowcube.eu/glossary/vulnerability-management/>) · [Zero-day vulnerability](<https://yellowcube.eu/glossary/zero-day-vulnerability/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Bug bounty](<https://yellowcube.eu/glossary/bug-bounty/>)

### Sources

[NIST SP 800-216](https://csrc.nist.gov/pubs/sp/800/216/final) · [CERT/CC: Coordinated Vulnerability Disclosure guidance](https://www.kb.cert.org/vuls/guidance/) · [CISA: Vulnerability Disclosure Policy Template](https://www.cisa.gov/vulnerability-disclosure-policy-template)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

