Report vulnerabilities through the required channels; before repair, do not publish details or exploit tools or send unpublished issues abroad
China's Network Product Security Vulnerability Management Provisions apply to individuals too. They restrict publication before a fix, details about vulnerabilities in systems currently in use, and dedicated exploitation tools. Public disclosures must include repair or prevention measures. Unpublished vulnerabilities may not be provided to overseas organizations or individuals other than the product provider.
What it takes
Free. Report to the product provider or an official platform. Do not publish details or proof-of-concept code before the vendor supplies a repair.
What you may gain
The Chinese provisions cover domestic network-product providers, network operators, and organizations or individuals discovering, collecting or publishing vulnerabilities. No one may use vulnerabilities to endanger cybersecurity or illegally collect, sell or publish vulnerability information. Public disclosure has five conditions: do not publish before the provider supplies repair measures; do not disclose vulnerability details in operators' currently used networks, information systems or equipment; do not deliberately exaggerate risks or exploit information for malicious hype or fraud; do not publish or supply programs and tools specifically for harmful exploitation; and publish repair or prevention measures simultaneously. Unpublished information must not be supplied to overseas parties other than the provider. Reports are encouraged to four official channels: the Ministry of Industry and Information Technology's cybersecurity-threat and vulnerability-sharing platform; the National Network and Information Security Information Reporting Center's vulnerability platform; CNCERT's vulnerability platform; and the China Information Technology Security Evaluation Center's vulnerability database. MIIT and the Ministry of Public Security address violations according to their responsibilities, using Cybersecurity Law penalties where applicable. Publishing cybersecurity information such as system vulnerabilities contrary to national rules can bring correction orders, warnings and optional RMB 10,000–100,000 fines. Refusal or serious circumstances can bring RMB 100,000–1 million, suspension of related business, shutdown for rectification, closure of websites or apps, or revocation of relevant permits or business licenses. Responsible managers and other directly responsible people face RMB 10,000–100,000. These rules apply nationwide in China.
Context & considerations
Individuals are expressly included; being a hobbyist is no exception. Submitting an unpublished domestic-system vulnerability to an overseas bug-bounty platform falls within the overseas-disclosure issue. Authorization to test and handling a discovered issue are separate questions. A lawfully found issue can be unlawfully disclosed; unauthorized testing can create problems at both stages. MIIT and CNCERT are commonly used reporting channels. The provisions do not separately address a vendor that was notified but refuses to repair; retain the report and negotiation history and also report through an official platform.
Research & references
MIIT, Cyberspace Administration of China and Ministry of Public Security (2021). Network Product Security Vulnerability Management Provisions, document [2021] No. 66, Articles 2, 4, 9, 10 and 14, effective September 1, 2021. https://www.gov.cn/gongbao/content/2021/content_5641351.htm; NPC Standing Committee (2025). Cybersecurity Law, 2025 revision effective January 1, 2026, Articles 28 and 65; formerly Articles 26 and 62. Article 14 of the vulnerability provisions cites the 2016 numbering. https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm