Security Advisories
Flock builds technology that public safety agencies, private organizations, and communities rely on. When we find or receive a report of a security vulnerability in one of our products, we fix it - and, where it affects the people who deploy and operate our products, we tell you about it publicly.
This page is where we do that.
Published advisories
Flock has not yet published a security advisory under this policy. As we publish them, they will be listed here, newest first.
Advisory records are also available through the CVE List at cve.org and downstream databases such as the National Vulnerability Database.
What a security advisory is
A security advisory is our public record of a vulnerability in a Flock product or service. Each advisory we publish will describe:
- The affected product, service, or firmware version
- What the vulnerability is and what an attacker could do with it
- Our severity assessment
- The CVE identifier assigned to the issue
- Credit to the reporting researcher, where they have asked to be credited
We publish an advisory when a patch or mitigation is available, coordinated with the reporting researcher where possible. Our full timeline commitments, including what happens when a fix takes longer than expected, are in our Vulnerability Disclosure Policy.
Reporting a vulnerability
If you have found a security vulnerability in a Flock product or service, email vulnerability.reporting@flocksafety.com. Our Vulnerability Disclosure Policy explains what is in scope, what to include in your report, what you can expect from us, and the safe harbor we extend to good-faith research.
.webp)








