bind-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
1
In Scope
8
Out of Scope
In-Scope Assets (1)
AssetCategoryBountyQuick Links
https://gitlab.isc.org/isc-projects/bind9OPEN-SOURCEYes-
Out-of-Scope Assets (8)
AssetCategoryBounty
Any asset that is not explicitly included in our program's scopeOTHERYes
Any depreciated versions and other versions than the current stable/official version are considered out of scope.OTHERYes
Any local implementation of the project/implementation belonging to third partiesOTHERYes
Any third parties’ or Community’s assets (e.g. packages or versions not created and published by ISC).OTHERYes
Any vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, DNS update)..OTHERYes
Vulnerabilities in the DNS protocol that are not specific to the BIND 9 implementation (while we are interested in these, they are out of scope of this Bug Bounty program).OTHERYes
gitlab.isc.orgOTHERYes
lists.isc.orgOTHERYes
Scope Changes (43)
Apr 7, 2026
ChangeAssetCategoryScopeTime
Addedany vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update).OTHEROut of Scope08:21
Removedany vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update).OTHEROut of Scope08:21
Addedany vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update).OTHEROut of Scope07:21
Addedany vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update).OTHEROut of Scope07:21
Mar 26, 2026
ChangeAssetCategoryScopeTime
Removedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope16:06
Removedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope16:06
Removedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope16:06
Removedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope16:06
Removedhttps://gitlab.isc.org/isc-projects/bind9URLIn Scope16:06
Removedgitlab.isc.orgURLOut of Scope16:06
Removedlists.isc.orgURLOut of Scope16:06
Removedany asset that is not explicitly included in our program's scopeOTHEROut of Scope16:06
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://gitlab.isc.org/isc-projects/bind9URLIn Scope19:08
Addedgitlab.isc.orgURLOut of Scope19:08
Addedlists.isc.orgURLOut of Scope19:08
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope19:08
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope19:08
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope19:08
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope19:08
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope00:51
Addedhttps://gitlab.isc.org/isc-projects/bind9CODEIn Scope00:51
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope00:51
Addedlists.isc.orgURLOut of Scope00:51
Addedgitlab.isc.orgURLOut of Scope00:51
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope00:51
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope00:51
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope21:40
Removedhttps://gitlab.isc.org/isc-projects/bind9OPEN-SOURCEIn Scope21:40
Removedgitlab.isc.orgOTHEROut of Scope21:40
Removedlists.isc.orgOTHEROut of Scope21:40
Removedany asset that is not explicitly included in our program's scopeOTHEROut of Scope21:40
Removedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope21:40
Removedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope21:40
Removedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope21:40
Addedlists.isc.orgOTHEROut of Scope00:33
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope00:33
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope00:33
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope00:33
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope00:33
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope00:33
Addedgitlab.isc.orgOTHEROut of Scope00:33