Feed
Bounty Rolling

Vercel public bug bounty

Vercel pays up to $10,000 for critical reports in its public bug bounty, including open source projects. No deadline.

Vercel opened one public bug bounty that covers its platform products and its open source projects. The announcement is dated 24 September 2026. New findings in open source projects should be reported to this program. Reports already filed on the older open source program stay there and will still be reviewed.

Rewards follow severity. On Open Source Tier 1, a critical report pays from $5,250 to $10,000, a high report from $1,250 to $5,000, a medium report from $550 to $1,000, and a low report from $200 to $500. Open Source Tier 2 pays less: critical from $2,750 to $5,000, high from $750 to $2,500, medium from $250 to $500, and low from $50 to $200.

On the Vercel platform, a critical report pays from $3,500 to $5,500, a high report from $2,000 to $3,000, a medium report from $750 to $1,750, and a low report from $50 to $500. Vercel says these ranges are general guidelines based on CVSS severity, and that it decides the final reward. The base bounty listed for the program is $50.

Submit the report on HackerOne with clear steps to reproduce the issue. The program went live on 21 September 2026. It has no deadline, and the HackerOne page lists submissions as open.

Source · vercel.com/blog/the-vercel-bug-bounty-program-is-now-publicly-available Published 24 September 2026 · Added here 25 September 2026