Feed
Bounty Rolling

GitHub Bug Bounty Program

GitHub pays $250 to $10,000 per valid report in its public bug bounty and $30,000 or more for critical findings in the invite only VIP tier. Open year round on HackerOne.

The GitHub Bug Bounty Program pays security researchers for vulnerabilities in GitHub products. In July 2026 GitHub restructured the program to favor quality over quantity. The new structure took effect on July 27, 2026, and submissions made before that date are honored under the old rules.

The public program now uses fixed payouts instead of ranges: $250 for low severity, $2,000 for medium, $5,000 for high and $10,000 for critical findings. GitHub also added a permanent VIP program. It is an invite only tier for researchers with a record of consistent quality, with higher payouts, up to $30,000 or more for critical findings, and faster responses.

Researchers qualify for the VIP tier with at least one critical finding, two high findings, four medium findings or seven low findings. New participants without an established record get up to four initial submissions to show their ability before submission limits apply.

Reports are submitted through HackerOne. The scope, rules and frequently asked questions are on the bounty program site. GitHub says it wants to reward deep, thoughtful research while keeping the program open to the wider security research community.

Source · github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program Published 22 July 2026 · Added here 7 September 2026