Coordinated Disclosure Policy
Ciphraxis generally follows coordinated vulnerability disclosure. Disclosure timing may depend on vulnerability severity, exploitation risk, vendor responsiveness, remediation availability, and public safety.
1. Validation
A suspected vulnerability is validated before it is treated as a research finding.
2. Vendor Contact
Ciphraxis attempts to contact the affected vendor or maintainer through an appropriate security channel.
3. Sanitized Advisory
When appropriate, Ciphraxis may publish a sanitized CRX advisory while coordination is ongoing. Such an advisory may contain a CRX identifier, preliminary severity and CVSS, CVE state, disclosure state, and a validated impact summary.
4. Technical Withholding
Technical details that would materially enable exploitation may remain withheld during remediation.
5. Remediation
When a patch or mitigation becomes available, the advisory may be updated.
6. Public Disclosure
After coordinated disclosure, remediation, or another appropriate disclosure point, Ciphraxis may publish additional technical analysis.
CRX IDENTIFIERS
Ciphraxis advisories use identifiers such as CRX-2026-001. These identifiers remain stable throughout the disclosure lifecycle. A later CVE assignment does not replace the CRX identifier; the CRX advisory remains the canonical Ciphraxis research record.
PRELIMINARY CVSS
When Ciphraxis publishes a CVSS assessment before an external authority or CNA publishes one, it is identified as a Ciphraxis preliminary assessment. Preliminary scores are not official NVD/CNA scores. Scores may change as technical understanding improves, vendor information becomes available, or scope changes.
CVE STATE
Advisories clearly distinguish between CVE assignment states. We do not use "PENDING" as a universal generic state.
- NOT ASSIGNEDNo CVE identifier exists for this issue.
- REQUESTEDAn actual CVE request has been submitted to an appropriate CNA.
- ASSIGNEDA CVE has been officially assigned.
REDACTION POLICY
Sanitized advisories may withhold affected product identity, specific vulnerable components, endpoints, payloads, proof-of-concepts, source locations, specific exploitation primitives, or affected version details when publishing that information would materially increase exploitation risk. This decision depends on the disclosure state and risk.
PUBLIC REPOSITORY POLICY
Embargoed vulnerability details are not stored in the public website repository. Redacted values are not hidden with CSS or client-side tricks; they are absent from the public output entirely.