Security

The posture, written down — including what it does not cover.

Hangar enforces deterministic policy on the MCP call path and records what happened. That draws a boundary, and a security page is only worth reading if it draws it honestly. These pages track the CVEs that matter to anyone running MCP servers, and map Hangar against the OWASP MCP Top 10 — marking the categories that are out of scope by design rather than claiming them.

Posture pages

Advisories

All posts

Every advisory is published in full on the blog. The ledger summarises and links to them — it does not replace them.

Reporting a vulnerability

Found something in Hangar itself? The disclosure process — where to send it and what to expect — is in the docs. Please do not open a public issue for a security report.

Security policy & disclosure