Step 1

Find a security issue

Find a vulnerability on an in-scope site. Only the sites and categories below are eligible.

In scope

Categories we accept

  • Remote code execution
  • Authentication or authorization flaws
  • Sensitive data exposure
  • Privilege escalation
  • Account takeover
  • Significant security misconfiguration with a verifiable vulnerability
  • Subdomain takeover, where the subdomain is owned and operated by Vultr

This list is closed. If your finding is not on this list, it is out of scope. We decide which category your report falls into. We decide whether a misconfiguration is significant.

Out of scopeWe will close your report if it is any of the following:

Not our systems

  • Customer infrastructure is explicitly out of scope
  • Vulnerabilities in customer content or customer configurations
  • Vulnerabilities in Vultr-provided ISO images
  • Marketplace products. The vendors manage these, not Vultr
  • Subdomain takeover of a customer-controlled domain or subdomain
  • GitHub repositories are not in scope for the bug bounty program. To report a vulnerability in a Vultr GitHub project, open an issue on that project

Attack types we do not accept

  • DoS and DDoS attacks. Do not test these. Testing them will get your account banned
  • Attacks that need MITM
  • Attacks that need physical access to a user's device
  • Attacks that need the victim's account to already be compromised
  • Content spoofing and text injection. We accept these only if you show a real attack vector, or show that you can change HTML or CSS
  • Clickjacking
  • Phishing attacks
  • Bugs that work only in an outdated browser

Not vulnerabilities

  • Missing security headers
  • Email configuration issues such as SPF, DKIM, and DMARC
  • Email address changes made before account verification
  • Reports about "+" or "." characters in Gmail addresses
  • Metadata in support tickets
  • Abuse of coupon codes, promotional credit, or the referral program

Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)

XSS and CSRF are out of scope.

Self-XSS is out of scope. A bug that only affects the user who triggers it is not a vulnerability.

We will read your report only if it proves
  • Remote code execution
  • Access to another user's personal data
  • Takeover of another user's account
To prove it, your report must contain
  • A proof of concept we can copy, paste, and run
  • Every step, from the injection point to the result above
We will close your report if it shows only
  • That injection is possible
  • That a CSRF token is missing
  • Text describing what an attacker could do, with no working demonstration

An alert box is not a proof of concept. A missing token is not a vulnerability.

Step 2

Write to us

Submit it on our report form with everything below. Your report must contain both a proof of concept and an impact statement.

What your report must contain

Required

  • A proof of concept we can copy, paste, and run to reproduce the issue
  • An impact statement that says what an attacker gains, and demonstrates it

How to send it

  • Paste your proof of concept into the description box
  • Do not send attachments. Our system deletes them automatically
  • Put videos on YouTube or Google Drive as unlisted. Paste the link into the description box

We will close your report if

  • We cannot reproduce the issue from what you sent us
  • It contains scanner output or automated tool output with no proof of concept
  • It is AI-generated and you did not verify it
  • It is low effort

Once we close your ticket, the decision is final. We will not reopen it. Do not submit the same report again.

Using AI toolsYou may use AI tools in your research. Your report must show that:

You understand the vulnerability
You checked the claims yourself
You built a working reproduction

We will close your report if you send us AI output or tool output that you did not verify yourself.

Step 3

Receive a reward

Wait for our security team to assess it. We rate accepted reports with Bugcrowd's Vulnerability Rating Taxonomy (VRT). Only P4 to P1 issues are paid. We assign the rating.

Rating Payout
P4 $50 - $300
P3 $300 - $500
P2 $500 - $1,000
P1 $1,000 - $10,000

Other Policies

  • Do not disclose a vulnerability publicly before we fix it
  • Follow Vultr's Terms of Service and all applicable laws
  • By participating, you agree to these terms. We may change this policy at any time

Report an issue

Thank you for your contribution to Vultr's security!

Remote Code Execution

Authentication or Authorization Flaw

Sensitive Data Exposure

Privilege Escalation

Account Takeover

Security Misconfiguration

Subdomain Takeover

Attachments are not accepted. Host videos on YouTube or Google Drive as unlisted and paste the link here.