U.S. flag

An official website of the United States government

Government Website

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Safely connect using HTTPS

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

  1. Home
  2. About DHS
  3. Site Links
  4. Report an IT Vulnerability
  5. Vulnerability Disclosure Form

Vulnerability Disclosure Form

Before submitting vulnerability information here, please read our vulnerability disclosure policy (VDP).

  • We only accept vulnerability reports through this form for certain systems; these are listed in our VDP.
  • We also accept emails at vulnerability.disclosure.prog@hq.dhs.gov and can engage in back-and-forth conversation there.
  • We do not support PGP-encrypted emails for vulnerability reports. For particularly sensitive information, use this (TLS-encrypted) form.

When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible.

  • Within 3 business days, we will acknowledge that your report has been received.  
  • To the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution.  
  • We will maintain an open dialogue to discuss issues.

Paperwork Reduction Act Burden Notice

An agency may not conduct or sponsor an information collection, and a person is not required to respond to a collection of information, unless it displays a currently valid Office of Management and Budget (OMB) control number. The public reporting burden for this collection of information is estimated at 3 hours. The OMB Control No. for this collection is 1601-0028. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing this burden to dhs.pra@hq.dhs.gov.

Privacy Statement

Authority: The Department of Homeland Security is authorized to collect this Personally Identifiable Information (PII) by and through the following authority: 5 U.S.C. 301; 44 U.S.C. 3101.
Purpose: The PII requested is being collected solely to conduct feedback and dialogue functions with submitters, as necessary.
Sharing Your Information: The information that you provide will be used by and disclosed to Federal Government personnel and contractors for the above-mentioned purpose. This includes using the information as necessary and authorized by the routine uses published in DHS/ALL-002 DHS Mailing and Other Lists System. Do not provide personal information beyond what is explicitly asked for in any of the provided data fields.
Disclosure: The disclosure of your PII is voluntary. However, a failure to provide your email information will inhibit our ability to provide feedback regarding the reported matter.