GitHub Security
  • Scope
  • Targets
  • Rules
  • Rewards
  • Ineligible Submissions About Blog FAQs
  • Submit a vulnerability

GitHub Bug Bounty

See More

Software security researchers are increasingly engaging with internet companies to hunt down vulnerabilities. Our bounty program gives a tip of the hat to these researchers and provides rewards of $30,000 or more for critical vulnerabilities.

If you have found a vulnerability, submit it here.

You can find useful information in our rules, scope, targets and FAQ sections.

Happy hacking!

  • Follow us on X
  • © 2026 GitHub, Inc.
  • Terms
  • Privacy
  • Security