Skip to main content

Report a Vulnerability

At Snyk, we value the security community and encourage community contributions to enhance the completeness and quality of our vulnerability database. 


Reporting a vulnerability in a Snyk product

If the vulnerability you want to report is related to a Snyk product, please refer to the Snyk VDP instead.


Reporting a missing vulnerability 

If you come across a known vulnerability that is not listed in our database, please email us at report@snyk.io. We will review your submission to understand why it may have been overlooked. If the vulnerability isn't addressed by an existing advisory, we will ensure it is added to the Snyk Vulnerability Database.

Note: Before reporting, please review our supported languages, package managers, and frameworks.


Reporting a new vulnerability in an open source project

At this time, we are pausing the acceptance of external vulnerability disclosures for open source projects. While we will continue to research, validate, and publish vulnerability intelligence through our internal processes, we want to explore better ways to provide disclosure assistance to researchers, maintainers, and the broader open-source community.