Blender

Blender

Top 10K site
VDPActive

Program Details

Blender's security team takes vulnerability reports by email and responds to every report within 14 days. Medium and high severity issues are patched within 60 days of becoming publicly known and critical ones shortly after they are reported, with updates shipped for both current and long term support releases. The team also tracks CVEs in the third-party libraries Blender ships. There is no bug bounty or compensation for security reports.

Response SLA
14 business days

Security

Preferred Languages
English, Dutch