Reporting to the NASA Vulnerability Disclosure Program on Bugcrowd is an incredibly rewarding experience. The security team is highly professional, and they genuinely value the efforts of the community in keeping their massive infrastructure secure. Receiving Hall of Fame recognition and a Letter of Appreciation from NASA is a fantastic milestone for any security researcher. When tackling a scope as vast as NASA's, you don't need to rely on noisy automated scanners. My biggest piece of advice for this program is to master Google Dorking. Advanced dorking is arguably the most powerful technique you can use here. It allows you to sift through the noise, map out forgotten assets, and identify edge cases or misconfigurations that standard tooling completely misses. If you take the time to refine your search parameters and manually investigate the architecture, you can uncover high-impact issues. I would highly recommend this program to anyone looking to make a meaningful impact and test their manual recon skills!
Work at NASA? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
3 publishedAs the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs and vendors.
| Month | Sev | Outcome | Why closed | Bounty |
|---|---|---|---|---|
| not set | Low | Not applicable | not set | not set |
| not set | Low | Not applicable | not set | not set |
| not set | Low | Not applicable | not set | not set |
NASA VDP is triaged by Bugcrowd team before handing it over to NASA officials for confirmation. I noticed that Bugcrowd's bot such as teapot_bugcrowd tends to mark report submissions as N/A. This was the case with my accepted report that earned me the NASA's LoR. I submitted a report in December 2024, but Bugcrowd's bot triaged it as N/A. Only in June 2025 did Bugcrowd's human triagers receive similar reports from other hackers, and they traced my report to be the first submission of its kind and marked my report as Accepted. The NASA VDP accepts only unique, non-duplicate reports that demonstrate a real security impact. However, my main critique of this program is related to a vulnerability I discovered. My report was closed as a duplicate of one submitted by another hacker over a year ago. Despite this long timeline, the affected endpoint remains completely unpatched, which I believe will cause more hackers to waste time and effort.
Log in to comment