1. Purpose and scope
Flowserve Product CERT provides a coordinated channel for potential vulnerabilities affecting Flowserve products, solutions, supporting software, and product-connected services. Reports should describe a security weakness with a plausible effect on confidentiality, integrity, availability, safety, or secure operation.
2. Reporting a vulnerability
Use the vulnerability report form to provide the affected product, version, technical description, reproduction steps, and observed impact. A name and email address are optional. Do not include live credentials, regulated personal data, or information unrelated to the technical report.
Submit separate reports for unrelated issues. Select the active-exploitation option when malicious use has been observed so the intake team can prioritize operational risk.
3. Handling process
Product CERT records the report, performs initial triage, identifies the responsible product team, validates the issue, and assesses affected products and versions. Confirmed issues move through remediation testing and a documented disclosure decision.
Coordination timing depends on technical complexity, safety implications, affected product support status, third-party dependencies, and the availability of a safe customer action.
4. Coordinated disclosure
Flowserve works with reporters and relevant coordinators toward a disclosure date that gives customers a practical opportunity to reduce risk. A published advisory may include severity, identifiers, affected versions, remediation or mitigation guidance, references, and reporter credit when requested and approved.
Product CERT may accelerate communication when active exploitation, material safety impact, or broad public knowledge changes the risk to customers.
5. Good-faith security research
Flowserve intends to support research performed to identify and report security issues responsibly.
6. Out of scope activity
- Denial-of-service or destructive testing against production systems
- Social engineering, phishing, or physical intrusion
- Accessing, retaining, or distributing other people’s data
- Testing third-party systems that Flowserve does not control
- Automated scanning that degrades service or operational safety
7. Data handling
Report information is restricted to personnel and service providers who require it for triage, remediation, legal review, safety response, and coordinated communication.
8. Contact and escalation
The production contact address and emergency escalation details are pending approval.
Open vulnerability reportDocument owner: Flowserve Product CERT. Approval and effective-date metadata will appear here before production publication.