bind-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
1
In Scope
7
Out of Scope
In-Scope Assets (1)
AssetCategoryBountyQuick Links
https://gitlab.isc.org/isc-projects/bind9OPEN-SOURCEYes-
Out-of-Scope Assets (7)
AssetCategoryBounty
Any asset that is not explicitly included in our program's scopeOTHERYes
Any depreciated versions and other versions than the current stable/official version are considered out of scope.OTHERYes
Any local implementation of the project/implementation belonging to third partiesOTHERYes
Any third parties’ or Community’s assets (e.g. packages or versions not created and published by ISC).OTHERYes
Vulnerabilities in the DNS protocol that are not specific to the BIND 9 implementation (while we are interested in these, they are out of scope of this Bug Bounty program).OTHERYes
gitlab.isc.orgOTHERYes
lists.isc.orgOTHERYes
Scope Changes (31)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://gitlab.isc.org/isc-projects/bind9URLIn Scope19:08
Addedgitlab.isc.orgURLOut of Scope19:08
Addedlists.isc.orgURLOut of Scope19:08
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope19:08
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope19:08
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope19:08
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope19:08
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope00:51
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope00:51
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope00:51
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope00:51
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope00:51
Addedhttps://gitlab.isc.org/isc-projects/bind9CODEIn Scope00:51
Addedgitlab.isc.orgURLOut of Scope00:51
Addedlists.isc.orgURLOut of Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedhttps://gitlab.isc.org/isc-projects/bind9OPEN-SOURCEIn Scope21:40
Removedgitlab.isc.orgOTHEROut of Scope21:40
Removedlists.isc.orgOTHEROut of Scope21:40
Removedany asset that is not explicitly included in our program's scopeOTHEROut of Scope21:40
Removedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope21:40
Removedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope21:40
Removedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope21:40
Removedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope21:40
Addedgitlab.isc.orgOTHEROut of Scope00:33
Addedlists.isc.orgOTHEROut of Scope00:33
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope00:33
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope00:33
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope00:33
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope00:33
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope00:33