Vulnerability Disclosure Policy
As a global leader in media as well as SaaS for publishing, The Washington Post embraces responsible software development norms. To support a healthy internet ecology, we are sharing our Vulnerability Disclosure Policy. This policy describes the submission process for security researchers wanting to share their findings with our engineering teams.

TL;DR
- The Washington Post is publishing its Vulnerability Disclosure Policy to encourage responsible disclosure of security findings.
- The policy outlines commitments to researchers, including confidentiality and timely remediation of serious issues.
- Researchers are requested to maintain confidentiality, provide detailed reproduction steps, and avoid out-of-scope testing.
- Out-of-scope activities include physical security testing, social engineering, DoS/DDoS attacks, and testing third-party SaaS apps.
- In-scope examples include various web vulnerabilities such as BOLAs/IDORs, OWASP API Top 10, and authentication flaws.