New Jun 30, 2026

Group Note Draft: W3C Standards Vulnerability Disclosure & Handling Process and Policy

Browsers, engines, etc. All from W3C - News View Group Note Draft: W3C Standards Vulnerability Disclosure & Handling Process and Policy on w3.org

The Security Interest Group has published the first draft of a Group Note titled W3C Standards Vulnerability Disclosure & Handling Process and Policy. This document defines how to report suspected security vulnerabilities in W3C standards and specifications (technical reports), so that issues can be triaged, confirmed, and resolved through the appropriate W3C processes. It is not for reporting vulnerabilities in software implementations or W3C operational infrastructure (see Out of scope).

Scroll to top