Dev48
Language
  • About
  • Services
  • Industries
  • Technologies
  • Articles
  • Contacts
Book a call
    Home/Articles/The vercel bug bounty program is now publicly available 2
Dev48

© 2026 · All rights reserved.

The Vercel Bug Bounty Program is now publicly available

Источник: Vercel

The Vercel Bug Bounty Program is now publicly available

Source: Vercel

Vercel's Bug Bounty Program is now public on HackerOne, covering all Vercel products and open-source projects. Learn how to participate and report findings.

September 28, 2026•Updated: September 28, 2026

In 2022, we launched a private bug bounty program through HackerOne. Over the last several years, we've worked with HackerOne's VIP program to refine our process, targets, and scope, onboarding thousands of their best researchers and hardening security across our platform.

We've translated those learnings into several public bounty programs:

Today, we are combining our private and OSS bounty programs into a single, public Vercel bug bounty program.

Copy link to headingWhy now

AI has fundamentally changed the nature of bug bounty programs, exponentially increasing the number of reports, both valid and invalid. Some companies are responding by moving to private programs.

At Vercel, we’ve found that public reports are still surfacing real, valuable findings. AI enables a much wider range of researchers to discover vulnerabilities, and we believe in evaluating reports on their own merit, so making our entire program public was the logical choice.

In preparation for the public launch, our security engineering team has streamlined our process and built tooling to filter out noise and expedite remediation. We have improved every step, from triaging reports to shipping and verifying fixes.

Our team and processes have been battle tested through our private program and several large public programs in the recent past. We are ready to open a comprehensive program to the public and have the best researchers out there responsibly explore every part of the platform.

Copy link to headingWhat is covered

All products across the Vercel platform and our open-source projects are now part of our unified public program. Read the Scope page on HackerOne for full details on what is covered.

Consolidation makes sense for our processes, but we also received feedback from the research community that having multiple programs made disclosure confusing because there were multiple places to submit reports. A single program simplifies reporting across our platform and open-source projects.

New findings in our open-source projects should be reported to the main Vercel program, but if you already have submissions to the previous OSS program, you don't need to copy them over. We will still review every submission that was made through that program.

Copy link to headingHow to participate

If you’re a security researcher, visit our HackerOne program page for details, bounties, and guidelines.

To file a report, submit your findings through HackerOne with clear reproduction steps. Our security team reviews every submission and works with researchers via the disclosure process. We're committed to fast response times and transparent communication.

We appreciate the researchers who take the time to dig into our code and report issues responsibly. We would also like to thank all the researchers who have been working in our private program. You have helped build the foundation for this public program, and nothing will change for you. We look forward to your future submissions.

Learn more about security at Vercel.

Copy link to headingJoin our security team

If this kind of work excites you, we are hiring. Apply to join the Vercel security team.

← All articles

More in Software Development

All →
Air Teams: Bring Your Best Agentic Workflows to the Whole Team – and Automate Repeatable Work
JetBrains

Air Teams: Bring Your Best Agentic Workflows to the Whole Team – and Automate Repeatable Work

Rider 2026.2.3 Is Released!
JetBrains

Rider 2026.2.3 Is Released!

A More Reliable Compilation Scheme for Kotlin Multiplatform Modules
JetBrains

A More Reliable Compilation Scheme for Kotlin Multiplatform Modules

BOB in Hotel Industry: Business on Books & OTB Guide
Hotelogix

BOB in Hotel Industry: Business on Books & OTB Guide

Insyde® Software Affirms Firmware Security Thought Leadership at FTA 2026
Insyde Software

Insyde® Software Affirms Firmware Security Thought Leadership at FTA 2026

Sennheiser Momentum 5 review: Great sound, incredible battery life, and few compromisesПресса
Momentum

Sennheiser Momentum 5 review: Great sound, incredible battery life, and few compromises

More from Vercel

Upcoming Next.js September Security Release
Vercel

Upcoming Next.js September Security Release

Next.js Security Update for a Critical Upstream Issue
Vercel

Next.js Security Update for a Critical Upstream Issue

Upcoming Next.js Security Update for a Critical Upstream Issue
Vercel

Upcoming Next.js Security Update for a Critical Upstream Issue

How we closed 1,500 GitHub issues in one month
Vercel

How we closed 1,500 GitHub issues in one month

Open-weight models take 56% of token volume, Astra doubles Fable 5.1 spend
Vercel

Open-weight models take 56% of token volume, Astra doubles Fable 5.1 spend

Reproducing, disclosing, and fixing the libheif vulnerability with Hacktron and the maintainers
Vercel

Reproducing, disclosing, and fixing the libheif vulnerability with Hacktron and the maintainers