FailSafe Research Initiative

Project

GlassBreak

Project GlassBreak is FailSafe's public-good responsible disclosure program. We identify vulnerabilities across open-source repositories and public-facing systems, report them responsibly, and contribute fixes upstream where possible.

Our aim is straightforward: make the software everyone builds on safer, protect the organizations people rely on, and give back to the community.

77
Organizations and projects
180+
Findings disclosed
0
Exploit instructions on this page

Our approach

Share what helps. Withhold what harms.

GlassBreak gives back to the open-source community through responsible reports and upstream fixes. The program also covers coordinated disclosures made privately to organizations.

We coordinate timing with maintainers and affected teams. Private disclosures receive public-safe summaries; open-source entries are grouped into simple program-level statuses, with linked upstream records serving as the detailed source of truth.

Disclosure process

How it works

A remediation-first process from discovery to a safe public record.

  1. 01

    Identify

    We identify security weaknesses in open-source repositories and public-facing systems.

  2. 02

    Notify

    We notify the security or engineering team directly with full details.

  3. 03

    Remediate

    We support maintainers and affected teams as they validate and fix the issue.

  4. 04

    Publish

    We record a public-safe summary or link the upstream contribution when appropriate.

GlassBreak registry

Responsible disclosures

Summaries are deliberately limited to information that cannot be used to reproduce or exploit a finding.

Publication note: Research areas are intentionally broad. Our summaries omit affected systems, exploit paths, personal data types, credentials, and other details that could increase risk. Public open-source entries link to their upstream records. Inclusion is not a commercial relationship or endorsement.
77 resultsPage 1 / 6
Medium 3
File and path safetyObject integrityNetwork request security

Impact proxy: Data confidentiality · Application integrity · Platform resilience · Transaction and trust integrity

Completed
Critical 5High 8
API access controlData protectionCloud and network securityIdentity and session security

Impact proxy: Data confidentiality · Account and access security · Application integrity · Platform resilience

In progress
High 2Medium 1
Identity and accessApplication logic

Impact proxy: Account and access security · Application integrity

Disclosed
Critical 1High 1
Data protectionInfrastructure security

Impact proxy: Data confidentiality · Platform resilience

Disclosed
High 2
Application data protectionIdentity security

Impact proxy: Data confidentiality · Account and access security · Application integrity

Remediated
High 1
Identity and web security

Impact proxy: Account and access security · Application integrity

Disclosed
Critical 1High 4
Data protectionSecrets and access control

Impact proxy: Data confidentiality · Account and access security

Remediated
Critical 4High 1
Data protectionAPI and infrastructure security

Impact proxy: Data confidentiality · Application integrity · Platform resilience

Disclosed
Critical 1High 2
Secrets managementData protection

Impact proxy: Data confidentiality · Account and access security

Disclosed
Critical 1High 1
Data access controlWeb application security

Impact proxy: Data confidentiality · Account and access security · Application integrity

Disclosed
Medium 1
Resource limitsAvailability

Impact proxy: Platform resilience · Service resilience

In progress

Contact GlassBreak

If your organization or project has received a GlassBreak disclosure and you'd like to coordinate remediation, update a listing, or request removal, contact our security team.

[email protected]

Questions & answers

Frequently asked questions

How GlassBreak coordinates, publishes, and maintains responsible disclosures.

Project GlassBreak is FailSafe's public-good responsible-disclosure program for open-source repositories and public-facing systems.

GlassBreak identifies a security weakness, notifies the relevant maintainers or security team privately, supports remediation, and publishes a safe record when appropriate.

No. Private disclosure summaries deliberately omit affected systems, exploit paths, personal data types, credentials, and other details that could increase risk.

The registry uses four program-level statuses: Remediated for confirmed fixes, Completed for concluded upstream work, In progress for active upstream review, and Disclosed when a safe public record exists without a confirmed remediation outcome.

Contact [email protected] to coordinate remediation, correct a listing, or request removal from the public registry.