NVIDIA takes the security of its software products and source code seriously. Please do not report security vulnerabilities through GitHub issues, pull requests, or public discussions. If a potential vulnerability appears in a public GitHub thread, NVIDIA maintainers may limit public discussion and redirect the report to the appropriate private disclosure channel.
To report a potential security vulnerability in an NVIDIA product, use one of these private channels:
- Web: Security Vulnerability Submission Form
- Email: psirt@nvidia.com
- PGP: NVIDIA public PGP key for communication
Include the affected product or repository name, version or branch, vulnerability type, reproduction steps, proof-of-concept details when available, and potential impact.
NVIDIA does not currently operate a bug bounty program, but externally reported issues may be acknowledged when they are addressed under NVIDIA's coordinated vulnerability disclosure policy. For more information, see the NVIDIA PSIRT policies.
For security-related information, visit NVIDIA Product Security.