Early access: the directory is still filling out, and every rating here is a reported experience.
A+ Rating
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
NASA Bugcrowd
93/ 100
Would submit again 100%
Recommend to peers 100%
Skill to hunt Intermediate · 3.0/5
Pays advertised range 100%
Median first response Within 3 days
Payout fairness 4.5 / 5
Communication 3.3 / 5
Acceptance rate 40%
Reported practices
+ Credits researchers 3 reports
+ Responsive communication 1 report
+ Clear, honest scope 1 report
+ Respectful & professional 1 report
Downgrades severity 1 report
Write a review Claim this company profile

Work at NASA? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

3 published
Securing the Cosmos: Earning Hall of Fame with NASA
positive

Reporting to the NASA Vulnerability Disclosure Program on Bugcrowd is an incredibly rewarding experience. The security team is highly professional, and they genuinely value the efforts of the community in keeping their massive infrastructure secure. Receiving Hall of Fame recognition and a Letter of Appreciation from NASA is a fantastic milestone for any security researcher. When tackling a scope as vast as NASA's, you don't need to rely on noisy automated scanners. My biggest piece of advice for this program is to master Google Dorking. Advanced dorking is arguably the most powerful technique you can use here. It allows you to sift through the noise, map out forgotten assets, and identify edge cases or misconfigurations that standard tooling completely misses. If you take the time to refine your search parameters and manually investigate the architecture, you can uncover high-impact issues. I would highly recommend this program to anyone looking to make a meaningful impact and test their manual recon skills!

via Bugcrowd reports 1 1st reply Within 3 days resubmit yes recommends yes skill Intermediate
+ Credits researchers − Downgrades severity + Respectful & professional
Rathore · Aug 11, 2026 · Share ↗ 2 helpful
0 comments

Log in to comment

I submitted 3 SSRF findings across the NASA VRP scope - they all went informative
neutral

As the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs and vendors.

via Bugcrowd reports 3 1st reply Within 3 days resubmit yes
+ Clear, honest scope + Credits researchers + Responsive communication
Month Sev Outcome Why closed Bounty
not set Low Not applicable not set not set
not set Low Not applicable not set not set
not set Low Not applicable not set not set
Maliq Barnard ✓ verified · Aug 3, 2026 · Share ↗ 0 helpful
0 comments

Log in to comment

NASA's Highly Competitive VDP on Bugcrowd
positive

NASA VDP is triaged by Bugcrowd team before handing it over to NASA officials for confirmation. I noticed that Bugcrowd's bot such as teapot_bugcrowd tends to mark report submissions as N/A. This was the case with my accepted report that earned me the NASA's LoR. I submitted a report in December 2024, but Bugcrowd's bot triaged it as N/A. Only in June 2025 did Bugcrowd's human triagers receive similar reports from other hackers, and they traced my report to be the first submission of its kind and marked my report as Accepted. The NASA VDP accepts only unique, non-duplicate reports that demonstrate a real security impact. However, my main critique of this program is related to a vulnerability I discovered. My report was closed as a duplicate of one submitted by another hacker over a year ago. Despite this long timeline, the affected endpoint remains completely unpatched, which I believe will cause more hackers to waste time and effort.

via Bugcrowd resubmit yes
+ Credits researchers
aaronamran · Aug 3, 2026 · Share ↗ 1 helpful
1 comment
Maliq Barnard
Maliq Barnard 1mo ago
Which truly is such a dope flex man!

Log in to comment