Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
ourahealthoy/ouravulnerabilitydisclosureprogram
6
In Scope
1
Out of Scope
In-Scope Assets (6)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *.ouraring.com | WILDCARD | No | ||
| Any Oura related domain | OTHER | No | - | |
| Official Oura Ring Accessories | OTHER | No | - | |
| Oura Android App | ANDROID | No | - | |
| Oura Ring (Gen 3 to current) | HARDWARE | No | - | |
| Oura iOS App | IOS | No | - |
Out-of-Scope Assets (1)
| Asset | Category | Bounty | |
|---|---|---|---|
| Services not hosted/owned by Oura | OTHER | No |
Scope Changes (14)
Jun 2, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | *.ouraring.com | WILDCARD | In Scope | 14:26 |
| Added | oura android app | ANDROID | In Scope | 14:26 |
| Added | oura ios app | IOS | In Scope | 14:26 |
| Added | oura ring (gen 3 to current) | HARDWARE | In Scope | 14:26 |
| Added | any oura related domain | OTHER | In Scope | 14:26 |
| Added | official oura ring accessories | OTHER | In Scope | 14:26 |
| Added | services not hosted/owned by oura | OTHER | Out of Scope | 14:26 |
| Added | *.ouraring.com | WILDCARD | In Scope | 14:26 |
| Added | oura android app | ANDROID | In Scope | 14:26 |
| Added | oura ios app | IOS | In Scope | 14:26 |
| Added | oura ring (gen 3 to current) | HARDWARE | In Scope | 14:26 |
| Added | any oura related domain | OTHER | In Scope | 14:26 |
| Added | official oura ring accessories | OTHER | In Scope | 14:26 |
| Added | services not hosted/owned by oura | OTHER | Out of Scope | 14:26 |