Skip to main content
  • IETF Community Survey 2025

    Each year the IETF Community Survey provides a comprehensive assessment of community demographics, engagement patterns, and perceptions of organizational effectiveness. The full report from the 2025 edition is now available.

    14 Jul 2026
  • Birds of a Feather at IETF 126

    The IETF 126 Vienna meeting takes place 18–24 July 2026. As at every IETF meeting, alongside the established Working Groups there will be a handful of Birds-of-a-Feather (BoF) sessions—and these are often the most interesting place to watch where Internet standards work is heading next.

    2 Jul 2026
  • From Lab to RFC: A PhD Student's Journey through the IETF

    Martine Sophie Lenders has been regularly participating in the IETF for over a decade, starting with the IETF 93 meeting in Prague in 2015. She has authored several Internet-Drafts—two of which recently were published as RFCs—and at the same time works on a PhD at FU Berlin and as a research associate at TU Dresden. We asked a few questions about what her experience in the IETF has been like while pursuing an academic journey.

    1 Jul 2026
  • Suggested IETF 126 Sessions for Getting Familiar with New Topics

    These IETF 126 meeting sessions are likely to include discussions and proposals that are accessible to a broad range of Internet technologists whether they are new to the IETF or long-time participants.

    29 Jun 2026
  • IETF LLC Board Retreat 2026

    The IETF Administration LLC Board of Directors held its annual retreat 29-30 April 2026 in Amsterdam. In addition to all Board members, the IETF Executive Director, the Director of Finance, and the Board Secretary were present. Here is a short summary of the main points we discussed.

    4 Jun 2026

Filter by topic and date

Filter by topic and date

Reporting Protocol Vulnerabilities

22 Mar 2021

The Internet Engineering Task Force recognizes that security vulnerabilities will be discovered in IETF protocols and welcomes their critical evaluation by researchers. After consulting with the community, the Internet Engineering Steering Group (IESG) recently provided guidance on how to report vulnerabilities to ensure they are addressed as effectively as possible.

vulnerability alert

The full set of guidance is the best source for all the information about how to report vulnerabilities in IETF protocols, but a few details are worth highlighting.

First, the process covers vulnerabilities in protocols or other specifications in documents, such as RFCs, published by the IETF. Security issues in specific products, software, or services that implement the protocols must be addressed by the providers or maintainers of those specific products or services. The IETF does not have any formal means of contacting those parties. Vulnerabilities in any infrastructure or services that support the IETF, IRTF and IAB (such as those associated with the ietf.org, iab.org, irtf.org and rfc-editor.org domains) are the responsibility of the IETF Administration LLC, which has its own vulnerability disclosure policy.

Second depending on the nature of the report, there may be specific steps a reporter can take to expedite its handling, as detailed in the vulnerability reporting guidance. For published RFCs or Internet-Drafts (I-Ds) currently under consideration by an active working group, the working group is the proper forum to address the issue. For individuals Internet-Drafts, contact the document author(s). For working group I-Ds or RFCs for which there is no active working group, the general reporting email address can be used.

Finally, while the IETF values critical analysis of its work, it does not pay “bug bounties” for reported vulnerabilities. IETF processes for creating and maintaining protocol specifications are open and transparent with meeting and mailing list archives publicly available. The protocol vulnerability reporting guidance provides more detail about further considerations, including how complex or severe vulnerabilities might be addressed.

While the preferred approach to reporting IETF protocol vulnerabilities is to contact the person or group responsible for the document, as a last resort, reports can always be  sent by email to protocol-vulnerability@ietf.org. The IETF Security Area Directors will make their best effort to triage the report. We hope this guidance helps maintain and improve the security of the protocols and specifications on which the global Internet is built.


Share this page