Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

csosa-vdp

BugcrowdView on Bugcrowd
RawAI Enhanced
2
In Scope
0
Out of Scope
Scope Changes (10)
Mar 5, 2026
ChangeAssetCategoryScopeTime
Addedhttps://www.csosa.gov/URLIn Scope22:35
Added*.csosa.govURLIn Scope22:35
Added*.csosa.govWILDCARDIn Scope22:35
Addedhttps://www.csosa.gov/URLIn Scope22:35
Feb 25, 2026
ChangeAssetCategoryScopeTime
Added*.csosa.govWILDCARDIn Scope19:22
Addedhttps://www.csosa.gov/URLIn Scope19:22
Addedhttps://www.csosa.gov/URLIn Scope17:21
Added*.csosa.govURLIn Scope17:21
Addedhttps://www.csosa.gov/URLIn Scope17:21
Added*.csosa.govWILDCARDIn Scope17:21