How to Report Security Vulnerabilities: From Discovery to CVE-2026-21535
Finding a security vulnerability can be quite a story. In my case, it started with confusion when testing a feature or noticing something unexpected. After wider testing, you might confirm that something is broken or there could be an underlying issue. Then the real question kicks in: where do you report it, and how do you do it responsibly?
What do I need, and where do I report it?
If you don't work in this space daily, you mostly hear about CVE's. But do you actually need one for every vulnerability, and how do you get it?