JFrog Trust

Report A Vulnerability

Please do not share bulk reports from automated scanners. Those findings should be reviewed and validated by a security practitioner before submitting them to JFrog.

If you believe you have found a security issue, please report it to JFrog using one of these methods:


Please submit your report via our support portal.

Security Researchers:

Please submit your security report through our Vulnerability Disclosure Program or our Bug Bounty Program managed by HackerOne.

Both programs are private. We’re accepting invitations by email to security@jfrog.com.

You can also email us your security report at security@jfrog.com. (If you wish to encrypt your email message with our PGP key, you can download it here).

Vulnerability Disclosure Philosophy

All submitted reports are confidential and we’ll address them by their severity. Please do not disclose the issue publicly until we assess its impact and mitigate the risk. Bounty payments will only be awarded to researchers who submit vulnerabilities through our Bug Bounty program.


Vulnerability reports should include the following information:

  • Summary of the vulnerability
  • Vulnerability scope: Product and its version or cloud service
  • Vulnerability issue type, such as remote code execution, XSS, or SQL injection
  • Steps to reproduce
  • Any proof-of-concept
  • Supporting material / references
  • The potential impact of the vulnerability


Submit a vulnerability report to the JFrog Vulnerability Disclosure Program:

(Make sure you’re logged in with your HackerOne account)

Release Fast Or Die

Start Free Buy Now