Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
osmre-vdp
1
In Scope
1
Out of Scope
In-Scope Assets (1)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *.osmre.gov. | URL | No |
Out-of-Scope Assets (1)
| Asset | Category | Bounty | |
|---|---|---|---|
| Anything not explicitly listed as 'In Scope' | URL | No |
Scope Changes (10)
Mar 5, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | *.osmre.gov | URL | In Scope | 22:34 |
| Added | anything not explicitly listed as 'in scope' | URL | Out of Scope | 22:34 |
| Added | anything not explicitly listed as 'in scope' | URL | Out of Scope | 22:34 |
| Added | *.osmre.gov | WILDCARD | In Scope | 22:34 |
Feb 25, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | anything not explicitly listed as 'in scope' | URL | Out of Scope | 19:17 |
| Added | *.osmre.gov | WILDCARD | In Scope | 19:17 |
| Added | *.osmre.gov | URL | In Scope | 17:17 |
| Added | anything not explicitly listed as 'in scope' | URL | Out of Scope | 17:17 |
| Added | anything not explicitly listed as 'in scope' | URL | Out of Scope | 17:17 |
| Added | *.osmre.gov | WILDCARD | In Scope | 17:17 |