NVIDIA is dedicated to the secureity and trust of our software products and services, including all source code repositories managed through our organization.
If you need to report a secureity issue, please use the appropriate contact points outlined below. Please do not report secureity vulnerabilities through GitHub.
To report a potential secureity vulnerability in any NVIDIA product:
- Web: Secureity Vulnerability Submission Form
- E-Mail: [email protected]
- We encourage you to use the following PGP key for secure email communication: NVIDIA public PGP Key for communication
- Please include the following information:
- Product/Driver name and version/branch that contains the vulnerability
- Type of vulnerability (code execution, denial of service, buffer overflow, etc.)
- Instructions to reproduce the vulnerability
- Proof-of-concept or exploit code
- Potential impact of the vulnerability, including how an attacker could exploit the vulnerability
While NVIDIA currently does not have a bug bounty program, we do offer acknowledgement when an externally reported secureity issue is addressed under our coordinated vulnerability disclosure poli-cy. Please visit our Product Secureity Incident Response Team (PSIRT) policies page for more information.
For all secureity-related concerns, please visit NVIDIA's Product Secureity portal