vulns.co
/
GKData.io MCP

HackerOne · 2 min read

Netflix

Paid Bounty

Open current program Scope capture

What this record establishes

Scope capture

Published asset rows were captured. The full policy and eligibility were not individually reviewed.

Directory row 143; Active program checkbox checked; Bounties minimum displayed $50. Positive displayed minimum supports paid bounty listing. Policy and live submission availability unverified.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 30 published rows
AssetTypeGroup / eligibility
*.nflxext.comWILDCARDBounty eligible: Yes
api*.netflix.comWILDCARDBounty eligible: Yes
*.prod.ftl.netflix.comWILDCARDBounty eligible: Yes
*.prod.cloud.netflix.comWILDCARDBounty eligible: Yes
*.nflxvideo.netWILDCARDBounty eligible: Yes
*.prod.dradis.netflix.comWILDCARDBounty eligible: Yes
*.nflximg.netWILDCARDBounty eligible: Yes
*.nflxso.netWILDCARDBounty eligible: Yes
www.netflix.comURLBounty eligible: Yes
beacon.netflix.comURLBounty eligible: Yes
customerevents.netflix.comURLBounty eligible: Yes
secure.netflix.comURLBounty eligible: Yes
help.netflix.comURLBounty eligible: Yes
ichnaea.netflix.comURLBounty eligible: Yes
presentationtracking.netflix.comURLBounty eligible: Yes
nmtracking.netflix.comURLBounty eligible: Yes
meechum.netflix.comURLBounty eligible: Yes
Open Source - AtlasSOURCE_CODEBounty eligible: Yes
Corporate AssetsOTHERBounty eligible: Yes
Open Source - ZuulOTHERBounty eligible: Yes
MicrositesOTHERBounty eligible: Yes
Open Source - SpectatorOTHERBounty eligible: Yes
Secondary AssetsOTHERBounty eligible: Yes
Content Authorization TargetsOTHERBounty eligible: Yes
Netflix Mobile Application for AndroidGOOGLE_PLAY_APP_IDBounty eligible: Yes
Netflix Mobile Application for iOSAPPLE_STORE_APP_IDBounty eligible: Yes
Affiliates or entities such as recently acquired companiesOTHERBounty eligible: No
Content authorization vulnerabilities affecting only the in-browser playerOTHERBounty eligible: No
Low impact, individually exposed Google Docs with no common root cause (see “Publicly accessible Google Document or Drive Links” in the “Corporate Targets” section)OTHERBounty eligible: No
Netflix Gaming TargetOTHERBounty eligible: No
Out of scope · 9 published rows
AssetTypeGroup / eligibility
ir.netflix.comURLBounty eligible: No
ir.netflix.netURLBounty eligible: No
netflixinvestor.comURLBounty eligible: No
Open Source - ConsolemeOTHERBounty eligible: No
Open Source - WeepOTHERBounty eligible: No
Open Source - DispatchOTHERBounty eligible: No
Third party websites or systems hosted by non-Netflix entities Out of ScopeOTHERBounty eligible: No
Set-top-boxes, smart TVs, streaming sticks Out of ScopeOTHERBounty eligible: No
Assets associated with ReadyPlayerMeOTHERBounty eligible: No

Capture limits

  • Only the published asset table was captured; program rules and eligibility still require individual review.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03
  2. Published scope source Primary source · reviewed 2026-10-03

Appears in Discovery, Bounty. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software