vulns.co
/
GKData.io MCP

GitLab · 2 min read

GitLab Bug Bounty

GitLab · HackerOne. Policy reviewed 2026-10-02. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Privacy violations, disruption, unverified automated reports and third-party/customer installations are excluded. A shared mitigation generally receives one award; GitLab determines severity and payment.

Eligibility and submission status

Current employees are excluded; former employees, immediate family and potentially conflicted associates receive additional review. Reports require verifiable evidence.

An enabled submission link and no pause notice were observed, but submission acceptance was not tested or explicitly stated.

Advertised rewards

Advertised ranges: Low $100–$750; Medium $1,000–$2,500; High $5,000–$15,000; Critical $20,000–$35,000. Business impact and reduced category schedules affect awards.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 19 published rows
AssetTypeGroup / eligibility
*.gitlab.netWILDCARDBounty eligible: Yes
*.gitlab.orgWILDCARDBounty eligible: Yes
*.gitlap.comWILDCARDBounty eligible: Yes
customers.gitlab.comURLBounty eligible: Yes
registry.gitlab.comURLBounty eligible: Yes
gitlab.comURLBounty eligible: Yes
about.gitlab.comURLBounty eligible: Yes
docs.gitlab.comURLBounty eligible: Yes
design.gitlab.comURLBounty eligible: Yes
advisories.gitlab.comURLBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlabSOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlab-runnerSOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitalySOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlab-pagesSOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlab-shellSOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlab-vscode-extensionSOURCE_CODEBounty eligible: Yes
Your Own GitLab InstanceOTHERBounty eligible: Yes
Other non-production infrastructureOTHERBounty eligible: Yes
GitLab for Jira CloudOTHERBounty eligible: Yes
Out of scope · 25 published rows
AssetTypeGroup / eligibility
*.gitlab.cnWILDCARDBounty eligible: No
*.runway.gitlab.netWILDCARDBounty eligible: No
*.gitlab-private.orgWILDCARDBounty eligible: No
*.service-now.comWILDCARDBounty eligible: No
dashboards.gitlab.comURLBounty eligible: No
alerts.gitlab.comURLBounty eligible: No
support.gitlab.comURLBounty eligible: No
shop.gitlab.comURLBounty eligible: No
forum.gitlab.comURLBounty eligible: No
status.gitlab.comURLBounty eligible: No
partners.gitlab.comURLBounty eligible: No
aptly.gitlab.comURLBounty eligible: No
translate.gitlab.comURLBounty eligible: No
federal-support.gitlab.comURLBounty eligible: No
us-federal-gitlab.comURLBounty eligible: No
ir.gitlab.comURLBounty eligible: No
levelup.gitlab.comURLBounty eligible: No
gitlab.biterg.ioURLBounty eligible: No
gitlabsandbox.netURLBounty eligible: No
gitlabdemo.cloudURLBounty eligible: No
gitlabtraining.cloudURLBounty eligible: No
packages.gitlab.comURLBounty eligible: No
https://gitlab.com/gitlab-org/cli/SOURCE_CODEBounty eligible: No
https://gitlab.com/gitlab-org/opstrace/opstrace-uiSOURCE_CODEBounty eligible: No
https://gitlab.com/gitlab-org/opstrace/opstraceSOURCE_CODEBounty eligible: No

Review limitations

  • Browser-rendered policy reviewed; static retrieval returned a JavaScript placeholder.
  • Policy updated July 21, 2026; the displayed reward-table date is November 22, 2021. Its age is retained rather than assumed obsolete.
  • Only dollar signs appear; ISO currency and normalized bounds remain null. Full live policy includes additional conditions.

Sources and provenance

  1. GitLab Bug Bounty | Bounty Policy | HackerOne GitLab / HackerOne · reviewed 2026-10-02
  2. Published HackerOne structured scope GitLab · reviewed 2026-10-03

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software