Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
nubank
9
In Scope
4
Out of Scope
In-Scope Assets (9)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| https://apps.apple.com/br/app/nubank-conta-e-cart%C3%A3o/id814456780 | IOS | No | - | |
| https://nubank.com.br/ | OTHER | No | - | |
| https://nubank.com.co | OTHER | No | - | |
| https://nubank.com.mx | OTHER | No | - | |
| https://play.google.com/store/apps/details?id=com.nu.production&hl=pt_BR&gl=US&pli=1 | ANDROID | No | ||
| https://www.nuinvest.com.br/ | URL | No | ||
| prod-*.nu.com.co | URL | No | ||
| prod-*.nu.com.mx | URL | No | ||
| prod-*.nubank.com.br | URL | No |
Out-of-Scope Assets (4)
| Asset | Category | Bounty | |
|---|---|---|---|
| *.nat-a.nubank.com.br | OTHER | No | |
| *.nuinternational.com | URL | No | |
| NuCommunity endpoints (BR, MX, CO) | URL | No | |
| international.nubank.com.br | URL | No |