FailSafe Research Initiative

Project

GlassBreak

Project GlassBreak is FailSafe's public-good responsible disclosure program. We identify vulnerabilities across open-source repositories and public-facing systems, report them responsibly, and contribute fixes upstream where possible.

Our aim is straightforward: make the software everyone builds on safer, protect the organizations people rely on, and give back to the community.

101
Organizations and projects
240+
Findings disclosed
0
Exploit instructions on this page

Our approach

Share what helps. Withhold what harms.

GlassBreak gives back to the open-source community through responsible reports and upstream fixes. The program also covers coordinated disclosures made privately to organizations.

We coordinate timing with maintainers and affected teams. Private disclosures receive public-safe summaries; open-source entries are grouped into simple program-level statuses, with linked upstream records serving as the detailed source of truth.

Disclosure process

How it works

A remediation-first process from discovery to a safe public record.

  1. 01

    Identify

    We identify security weaknesses in open-source repositories and public-facing systems.

  2. 02

    Notify

    We notify the security or engineering team directly with full details.

  3. 03

    Remediate

    We support maintainers and affected teams as they validate and fix the issue.

  4. 04

    Publish

    We record a public-safe summary or link the upstream contribution when appropriate.

GlassBreak registry

Responsible disclosures

Summaries are deliberately limited to information that cannot be used to reproduce or exploit a finding.

Publication note: Research areas are intentionally broad. Our summaries omit affected systems, exploit paths, personal data types, credentials, and other details that could increase risk. Public open-source entries link to their upstream records. Inclusion is not a commercial relationship or endorsement.
101 resultsPage 1 / 7
Critical 1
Infrastructure and dependency security

Impact proxy: Platform resilience

Disclosed
Critical 1High 1
Secrets policyAuthentication controls

Impact proxy: Account and access security

In progress
Critical 1High 1
Data protectionInfrastructure security

Impact proxy: Data confidentiality · Platform resilience

Disclosed
High 2Medium 1
Identity and accessApplication logic

Impact proxy: Account and access security · Application integrity

Disclosed
Critical 1High 2
Secrets managementData protection

Impact proxy: Data confidentiality · Account and access security

Disclosed
High 2
Application data protectionIdentity security

Impact proxy: Data confidentiality · Account and access security · Application integrity

Remediated
High 1
Identity and web security

Impact proxy: Account and access security · Application integrity

Disclosed
Critical 1High 1
Data access controlWeb application security

Impact proxy: Data confidentiality · Account and access security · Application integrity

Disclosed
High 3
Transaction authorizationInfrastructure securityAdministrative access control

Impact proxy: Account and access security · Platform resilience · Transaction and trust integrity

In progress
Not rated 3
Signature validationTransaction authorization

Impact proxy: Account and access security · Transaction and trust integrity

In progress
High 1
Secrets managementSoftware supply chain

Impact proxy: Account and access security · Platform resilience

Disclosed

Contact GlassBreak

If your organization or project has received a GlassBreak disclosure and you'd like to coordinate remediation, update a listing, or request removal, contact our security team.

[email protected]

Questions & answers

Frequently asked questions

How GlassBreak coordinates, publishes, and maintains responsible disclosures.

Project GlassBreak is FailSafe's public-good responsible-disclosure program for open-source repositories and public-facing systems.

GlassBreak identifies a security weakness, notifies the relevant maintainers or security team privately, supports remediation, and publishes a safe record when appropriate.

No. Private disclosure summaries deliberately omit affected systems, exploit paths, personal data types, credentials, and other details that could increase risk.

The registry uses four program-level statuses: Remediated for confirmed fixes, Completed for concluded upstream work, In progress for active upstream review, and Disclosed when a safe public record exists without a confirmed remediation outcome.

Contact [email protected] to coordinate remediation, correct a listing, or request removal from the public registry.