netflix

HackerOneView on HackerOne
RawAI Enhanced
30
In Scope
9
Out of Scope
In-Scope Assets (30)
AssetCategoryBountyQuick Links
*.nflxext.comWILDCARDYes
*.nflximg.netWILDCARDYes
*.nflxso.netWILDCARDYes
*.nflxvideo.netWILDCARDYes
*.prod.cloud.netflix.comWILDCARDYes
*.prod.dradis.netflix.comWILDCARDYes
*.prod.ftl.netflix.comWILDCARDYes
Affiliates or entities such as recently acquired companiesOTHERNo-
Content Authorization TargetsOTHERYes-
Content authorization vulnerabilities affecting only the in-browser playerOTHERNo-
Corporate AssetsOTHERYes-
Low impact, individually exposed Google Docs with no common root cause (see “Publicly accessible Google Document or Drive Links” in the “Corporate Targets” section)OTHERNo-
MicrositesOTHERYes-
Netflix Gaming TargetOTHERNo-
Netflix Mobile Application for AndroidANDROIDYes-
Netflix Mobile Application for iOSIOSYes-
Open Source - AtlasCODEYes-
Open Source - SpectatorOTHERYes-
Open Source - ZuulOTHERYes-
Secondary AssetsOTHERYes-
api*.netflix.comWILDCARDYes
beacon.netflix.comURLYes
customerevents.netflix.comURLYes
help.netflix.comURLYes
ichnaea.netflix.comURLYes
meechum.netflix.comURLYes
nmtracking.netflix.comURLYes
presentationtracking.netflix.comURLYes
secure.netflix.comURLYes
www.netflix.comURLYes
Out-of-Scope Assets (9)
AssetCategoryBounty
Assets associated with ReadyPlayerMeOTHERNo
Open Source - ConsolemeOTHERNo
Open Source - DispatchOTHERNo
Open Source - WeepOTHERNo
Set-top-boxes, smart TVs, streaming sticks Out of ScopeOTHERNo
Third party websites or systems hosted by non-Netflix entities Out of ScopeOTHERNo
ir.netflix.comURLNo
ir.netflix.netURLNo
netflixinvestor.comURLNo
Scope Changes (108)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedlow impact, individually exposed google docs with no common root cause (see “publicly accessible google document or drive links” in the “corporate targets” section)OTHEROut of Scope19:19
Addedaffiliates or entities such as recently acquired companiesOTHERIn Scope19:19
AddedmicrositesOTHERIn Scope19:19
Addedsecure.netflix.comURLIn Scope19:19
Addedcorporate assetsOTHERIn Scope19:19
Addedopen source - zuulOTHERIn Scope19:19
Added*.nflxvideo.netWILDCARDIn Scope19:19
Added*.prod.ftl.netflix.comWILDCARDIn Scope19:19
Addedopen source - dispatchOTHEROut of Scope19:19
Addedopen source - weepOTHEROut of Scope19:19
Addednetflix mobile application for androidANDROIDIn Scope19:19
Addednetflix mobile application for iosIOSIn Scope19:19
Addedcontent authorization vulnerabilities affecting only the in-browser playerOTHEROut of Scope19:19
Addedcontent authorization targetsOTHERIn Scope19:19
Addedassets associated with readyplayermeOTHEROut of Scope19:19
Addednetflix gaming targetOTHEROut of Scope19:19
Addedichnaea.netflix.comURLIn Scope19:19
Addedbeacon.netflix.comURLIn Scope19:19
Added*.prod.dradis.netflix.comWILDCARDIn Scope19:19
Added*.prod.cloud.netflix.comWILDCARDIn Scope19:19
Addedhelp.netflix.comURLIn Scope19:19
Addedapi*.netflix.comWILDCARDIn Scope19:19
Addedir.netflix.comURLOut of Scope19:19
Addednmtracking.netflix.comURLIn Scope19:19
Addedpresentationtracking.netflix.comURLIn Scope19:19
Added*.nflximg.netWILDCARDIn Scope19:19
Addedopen source - atlasOTHERIn Scope19:19
Added*.nflxext.comWILDCARDIn Scope19:19
Addedthird party websites or systems hosted by non-netflix entities out of scopeOTHEROut of Scope19:19
Addednetflixinvestor.comURLOut of Scope19:19
Addedopen source - spectatorOTHERIn Scope19:19
Addedset-top-boxes, smart tvs, streaming sticks out of scopeOTHEROut of Scope19:19
Added*.nflxso.netWILDCARDIn Scope19:19
Addedopen source - consolemeOTHEROut of Scope19:19
Addedir.netflix.netURLOut of Scope19:19
Addedwww.netflix.comURLIn Scope19:19
Addedcustomerevents.netflix.comURLIn Scope19:19
Addedsecondary assetsOTHERIn Scope19:19
Addedmeechum.netflix.comURLIn Scope19:19
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedset-top-boxes, smart tvs, streaming sticks out of scopeOTHEROut of Scope00:47
Addedmeechum.netflix.comURLIn Scope00:47
Added*.nflxext.comWILDCARDIn Scope00:47
Addedopen source - atlasOTHERIn Scope00:47
Addedcorporate assetsOTHERIn Scope00:47
Addednmtracking.netflix.comURLIn Scope00:47
Added*.prod.cloud.netflix.comWILDCARDIn Scope00:47
Added*.nflxso.netWILDCARDIn Scope00:47
Addedichnaea.netflix.comURLIn Scope00:47
Addedcontent authorization targetsOTHERIn Scope00:47
Addedaffiliates or entities such as recently acquired companiesOTHERIn Scope00:47
Addedlow impact, individually exposed google docs with no common root cause (see “publicly accessible google document or drive links” in the “corporate targets” section)OTHEROut of Scope00:47
Addedopen source - weepOTHEROut of Scope00:47
Addedassets associated with readyplayermeOTHEROut of Scope00:47
Addedopen source - consolemeOTHEROut of Scope00:47
Addedopen source - dispatchOTHEROut of Scope00:47
Addednetflixinvestor.comURLOut of Scope00:47
Addedapi*.netflix.comWILDCARDIn Scope00:47
Added*.prod.dradis.netflix.comWILDCARDIn Scope00:47
Addedcustomerevents.netflix.comURLIn Scope00:47
Addedopen source - zuulOTHERIn Scope00:47
Addedthird party websites or systems hosted by non-netflix entities out of scopeOTHEROut of Scope00:47
Addedir.netflix.netURLOut of Scope00:47
Added*.nflxvideo.netWILDCARDIn Scope00:47
Addedpresentationtracking.netflix.comURLIn Scope00:47
AddedmicrositesOTHERIn Scope00:47
Addedopen source - spectatorOTHERIn Scope00:47
Addednetflix mobile application for androidANDROIDIn Scope00:47
Addedir.netflix.comURLOut of Scope00:47
Addedwww.netflix.comURLIn Scope00:47
Added*.prod.ftl.netflix.comWILDCARDIn Scope00:47
Addedbeacon.netflix.comURLIn Scope00:47
Addedsecure.netflix.comURLIn Scope00:47
Added*.nflximg.netWILDCARDIn Scope00:47
Addedhelp.netflix.comURLIn Scope00:47
Addedcontent authorization vulnerabilities affecting only the in-browser playerOTHEROut of Scope00:47
Addednetflix mobile application for iosIOSIn Scope00:47
Addedsecondary assetsOTHERIn Scope00:47
Addednetflix gaming targetOTHEROut of Scope00:47
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removed*.nflxext.comWILDCARDIn Scope21:39
Removednetflix mobile application for androidANDROIDIn Scope21:39
Removednetflix mobile application for iosIOSIn Scope21:39
Removedmeechum.netflix.comURLIn Scope21:39
Removedcontent authorization targetsOTHERIn Scope21:39
Removedsecondary assetsOTHERIn Scope21:39
Removedopen source - spectatorOTHERIn Scope21:39
RemovedmicrositesOTHERIn Scope21:39
Removedopen source - zuulOTHERIn Scope21:39
Removednmtracking.netflix.comURLIn Scope21:39
Removedpresentationtracking.netflix.comURLIn Scope21:39
Removedichnaea.netflix.comURLIn Scope21:39
Removedhelp.netflix.comURLIn Scope21:39
Removed*.nflxso.netWILDCARDIn Scope21:39
Removed*.nflximg.netWILDCARDIn Scope21:39
Removedsecure.netflix.comURLIn Scope21:39
Removedcustomerevents.netflix.comURLIn Scope21:39
Removedbeacon.netflix.comURLIn Scope21:39
Removed*.prod.dradis.netflix.comWILDCARDIn Scope21:39
Removed*.nflxvideo.netWILDCARDIn Scope21:39
Removedcorporate assetsOTHERIn Scope21:39
Removedopen source - atlasCODEIn Scope21:39
Removed*.prod.cloud.netflix.comWILDCARDIn Scope21:39
Removed*.prod.ftl.netflix.comWILDCARDIn Scope21:39
Removedapi*.netflix.comWILDCARDIn Scope21:39
Removedwww.netflix.comURLIn Scope21:39
Addedcontent authorization vulnerabilities affecting only the in-browser playerOTHERIn Scope19:12
Addednetflix gaming targetOTHERIn Scope19:12
Addedlow impact, individually exposed google docs with no common root cause (see “publicly accessible google document or drive links” in the “corporate targets” section)OTHERIn Scope19:12
Addedaffiliates or entities such as recently acquired companiesOTHERIn Scope19:12