NASA VDP is triaged by Bugcrowd team before handing it over to NASA officials for confirmation. I noticed that Bugcrowd's bot such as teapot_bugcrowd tends to mark report submissions as N/A. This was the case with my accepted report that earned me the NASA's LoR. I submitted a report in December 2024, but Bugcrowd's bot triaged it as N/A. Only in June 2025 did Bugcrowd's human triagers receive similar reports from other hackers, and they traced my report to be the first submission of its kind and marked my report as Accepted. The NASA VDP accepts only unique, non-duplicate reports that demonstrate a real security impact. However, my main critique of this program is related to a vulnerability I discovered. My report was closed as a duplicate of one submitted by another hacker over a year ago. Despite this long timeline, the affected endpoint remains completely unpatched, which I believe will cause more hackers to waste time and effort.
NR
Unrated
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
1 more review needed for a grade
Reported practices
+
Credits researchers
2 reports
+
Responsive communication
1 report
+
Clear, honest scope
1 report
Found a vulnerability?
NASA has not claimed a profile here. If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf — with your explicit permission — and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
2 publishedNASA's Highly Competitive VDP on Bugcrowd
★★★★★
positive
via Bugcrowd
resubmit yes
+ Credits researchers
I submitted 3 SSRF findings across the NASA VRP scope - they all went informative
★★★★★
neutral
As the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs and vendors.
via Bugcrowd
reports 3
1st reply Within 3 days
resubmit yes
+ Clear, honest scope
+ Credits researchers
+ Responsive communication
| Month | Sev | Outcome | Why closed | Bounty |
|---|---|---|---|---|
| — | Low | Not applicable | — | — |
| — | Low | Not applicable | — | — |
| — | Low | Not applicable | — | — |
0 comments
Log in to comment