netflix

HackerOneView on HackerOne
RawAI Enhanced
30
In Scope
9
Out of Scope
In-Scope Assets (30)
AssetCategoryBountyQuick Links
*.nflxext.comWILDCARDYes
*.nflximg.netWILDCARDYes
*.nflxso.netWILDCARDYes
*.nflxvideo.netWILDCARDYes
*.prod.cloud.netflix.comWILDCARDYes
*.prod.dradis.netflix.comWILDCARDYes
*.prod.ftl.netflix.comWILDCARDYes
Affiliates or entities such as recently acquired companiesOTHERNo-
Content Authorization TargetsOTHERYes-
Content authorization vulnerabilities affecting only the in-browser playerOTHERNo-
Corporate AssetsOTHERYes-
Low impact, individually exposed Google Docs with no common root cause (see “Publicly accessible Google Document or Drive Links” in the “Corporate Targets” section)OTHERNo-
MicrositesOTHERYes-
Netflix Gaming TargetOTHERNo-
Netflix Mobile Application for AndroidANDROIDYes-
Netflix Mobile Application for iOSIOSYes-
Open Source - AtlasCODEYes-
Open Source - SpectatorOTHERYes-
Open Source - ZuulOTHERYes-
Secondary AssetsOTHERYes-
api*.netflix.comWILDCARDYes
beacon.netflix.comURLYes
customerevents.netflix.comURLYes
help.netflix.comURLYes
ichnaea.netflix.comURLYes
meechum.netflix.comURLYes
nmtracking.netflix.comURLYes
presentationtracking.netflix.comURLYes
secure.netflix.comURLYes
www.netflix.comURLYes
Out-of-Scope Assets (9)
AssetCategoryBounty
Assets associated with ReadyPlayerMeOTHERNo
Open Source - ConsolemeOTHERNo
Open Source - DispatchOTHERNo
Open Source - WeepOTHERNo
Set-top-boxes, smart TVs, streaming sticks Out of ScopeOTHERNo
Third party websites or systems hosted by non-Netflix entities Out of ScopeOTHERNo
ir.netflix.comURLNo
ir.netflix.netURLNo
netflixinvestor.comURLNo
Scope Changes (108)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedcorporate assetsOTHERIn Scope19:19
Addedopen source - zuulOTHERIn Scope19:19
Added*.nflxvideo.netWILDCARDIn Scope19:19
Added*.prod.ftl.netflix.comWILDCARDIn Scope19:19
Addedopen source - dispatchOTHEROut of Scope19:19
Addedopen source - weepOTHEROut of Scope19:19
Addednetflix mobile application for androidANDROIDIn Scope19:19
Addednetflix mobile application for iosIOSIn Scope19:19
Addedcontent authorization vulnerabilities affecting only the in-browser playerOTHEROut of Scope19:19
Addedcontent authorization targetsOTHERIn Scope19:19
Addedassets associated with readyplayermeOTHEROut of Scope19:19
Addednetflix gaming targetOTHEROut of Scope19:19
Addedhelp.netflix.comURLIn Scope19:19
Addedapi*.netflix.comWILDCARDIn Scope19:19
Addedir.netflix.comURLOut of Scope19:19
Addedichnaea.netflix.comURLIn Scope19:19
Addednmtracking.netflix.comURLIn Scope19:19
Addedpresentationtracking.netflix.comURLIn Scope19:19
Added*.nflximg.netWILDCARDIn Scope19:19
Addedopen source - atlasOTHERIn Scope19:19
Added*.nflxext.comWILDCARDIn Scope19:19
Addednetflixinvestor.comURLOut of Scope19:19
Addedlow impact, individually exposed google docs with no common root cause (see “publicly accessible google document or drive links” in the “corporate targets” section)OTHEROut of Scope19:19
Addedaffiliates or entities such as recently acquired companiesOTHERIn Scope19:19
AddedmicrositesOTHERIn Scope19:19
Addedsecure.netflix.comURLIn Scope19:19
Addedopen source - spectatorOTHERIn Scope19:19
Addedset-top-boxes, smart tvs, streaming sticks out of scopeOTHEROut of Scope19:19
Added*.nflxso.netWILDCARDIn Scope19:19
Addedopen source - consolemeOTHEROut of Scope19:19
Addedir.netflix.netURLOut of Scope19:19
Addedwww.netflix.comURLIn Scope19:19
Addedcustomerevents.netflix.comURLIn Scope19:19
Addedsecondary assetsOTHERIn Scope19:19
Addedmeechum.netflix.comURLIn Scope19:19
Addedthird party websites or systems hosted by non-netflix entities out of scopeOTHEROut of Scope19:19
Added*.prod.cloud.netflix.comWILDCARDIn Scope19:19
Added*.prod.dradis.netflix.comWILDCARDIn Scope19:19
Addedbeacon.netflix.comURLIn Scope19:19
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedwww.netflix.comURLIn Scope00:47
Addedmeechum.netflix.comURLIn Scope00:47
Added*.nflxext.comWILDCARDIn Scope00:47
Addedopen source - atlasOTHERIn Scope00:47
Addedcorporate assetsOTHERIn Scope00:47
Addednmtracking.netflix.comURLIn Scope00:47
Added*.prod.cloud.netflix.comWILDCARDIn Scope00:47
Added*.nflxso.netWILDCARDIn Scope00:47
Addedichnaea.netflix.comURLIn Scope00:47
Addedcontent authorization targetsOTHERIn Scope00:47
Addedaffiliates or entities such as recently acquired companiesOTHERIn Scope00:47
Addedlow impact, individually exposed google docs with no common root cause (see “publicly accessible google document or drive links” in the “corporate targets” section)OTHEROut of Scope00:47
Addedopen source - weepOTHEROut of Scope00:47
Addedassets associated with readyplayermeOTHEROut of Scope00:47
Addedopen source - consolemeOTHEROut of Scope00:47
Addedopen source - dispatchOTHEROut of Scope00:47
Addednetflixinvestor.comURLOut of Scope00:47
Addedapi*.netflix.comWILDCARDIn Scope00:47
Added*.prod.dradis.netflix.comWILDCARDIn Scope00:47
Addedcustomerevents.netflix.comURLIn Scope00:47
Addedopen source - zuulOTHERIn Scope00:47
Addedthird party websites or systems hosted by non-netflix entities out of scopeOTHEROut of Scope00:47
Addedir.netflix.netURLOut of Scope00:47
Added*.nflxvideo.netWILDCARDIn Scope00:47
Addedpresentationtracking.netflix.comURLIn Scope00:47
AddedmicrositesOTHERIn Scope00:47
Addedopen source - spectatorOTHERIn Scope00:47
Addednetflix mobile application for androidANDROIDIn Scope00:47
Addedir.netflix.comURLOut of Scope00:47
Added*.prod.ftl.netflix.comWILDCARDIn Scope00:47
Addedbeacon.netflix.comURLIn Scope00:47
Addedsecure.netflix.comURLIn Scope00:47
Added*.nflximg.netWILDCARDIn Scope00:47
Addedhelp.netflix.comURLIn Scope00:47
Addedcontent authorization vulnerabilities affecting only the in-browser playerOTHEROut of Scope00:47
Addednetflix mobile application for iosIOSIn Scope00:47
Addedsecondary assetsOTHERIn Scope00:47
Addedset-top-boxes, smart tvs, streaming sticks out of scopeOTHEROut of Scope00:47
Addednetflix gaming targetOTHEROut of Scope00:47
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removed*.nflxext.comWILDCARDIn Scope21:39
Removednetflix mobile application for androidANDROIDIn Scope21:39
Removednetflix mobile application for iosIOSIn Scope21:39
Removedmeechum.netflix.comURLIn Scope21:39
Removedcontent authorization targetsOTHERIn Scope21:39
Removedsecondary assetsOTHERIn Scope21:39
Removedopen source - spectatorOTHERIn Scope21:39
RemovedmicrositesOTHERIn Scope21:39
Removedopen source - zuulOTHERIn Scope21:39
Removednmtracking.netflix.comURLIn Scope21:39
Removedpresentationtracking.netflix.comURLIn Scope21:39
Removedichnaea.netflix.comURLIn Scope21:39
Removedhelp.netflix.comURLIn Scope21:39
Removed*.nflxso.netWILDCARDIn Scope21:39
Removed*.nflximg.netWILDCARDIn Scope21:39
Removedsecure.netflix.comURLIn Scope21:39
Removedcustomerevents.netflix.comURLIn Scope21:39
Removedbeacon.netflix.comURLIn Scope21:39
Removed*.prod.dradis.netflix.comWILDCARDIn Scope21:39
Removed*.nflxvideo.netWILDCARDIn Scope21:39
Removedcorporate assetsOTHERIn Scope21:39
Removedopen source - atlasCODEIn Scope21:39
Removed*.prod.cloud.netflix.comWILDCARDIn Scope21:39
Removed*.prod.ftl.netflix.comWILDCARDIn Scope21:39
Removedapi*.netflix.comWILDCARDIn Scope21:39
Removedwww.netflix.comURLIn Scope21:39
Addedaffiliates or entities such as recently acquired companiesOTHERIn Scope19:12
Addedcontent authorization vulnerabilities affecting only the in-browser playerOTHERIn Scope19:12
Addedlow impact, individually exposed google docs with no common root cause (see “publicly accessible google document or drive links” in the “corporate targets” section)OTHERIn Scope19:12
Addednetflix gaming targetOTHERIn Scope19:12