Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

osmre-vdp

BugcrowdView on Bugcrowd
RawAI Enhanced
1
In Scope
1
Out of Scope
In-Scope Assets (1)
Out-of-Scope Assets (1)
Scope Changes (20)
Aug 12, 2026
ChangeAssetCategoryScopeTime
Added*.osmre.govURLIn Scope12:58
Addedanything not explicitly listed as 'in scope'URLOut of Scope12:58
Addedanything not explicitly listed as 'in scope'URLOut of Scope12:58
Added*.osmre.govWILDCARDIn Scope12:58
Jun 26, 2026
ChangeAssetCategoryScopeTime
Program Removed06:34
Jun 17, 2026
ChangeAssetCategoryScopeTime
Added*.osmre.govURLIn Scope11:37
Addedanything not explicitly listed as 'in scope'URLOut of Scope11:37
Added*.osmre.govWILDCARDIn Scope11:37
Addedanything not explicitly listed as 'in scope'URLOut of Scope11:37
Program Removed10:34
Mar 5, 2026
ChangeAssetCategoryScopeTime
Added*.osmre.govURLIn Scope22:34
Addedanything not explicitly listed as 'in scope'URLOut of Scope22:34
Addedanything not explicitly listed as 'in scope'URLOut of Scope22:34
Added*.osmre.govWILDCARDIn Scope22:34
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedanything not explicitly listed as 'in scope'URLOut of Scope19:17
Added*.osmre.govWILDCARDIn Scope19:17
Added*.osmre.govURLIn Scope17:17
Addedanything not explicitly listed as 'in scope'URLOut of Scope17:17
Addedanything not explicitly listed as 'in scope'URLOut of Scope17:17
Added*.osmre.govWILDCARDIn Scope17:17