vulns.co
/
GKData.io MCP

DEInformation exposure and response privacy · 2 min read

Facebook error responses exposed unintended application data

Facebook confirms a USD 65,000 bounty payment for an error-response data-exposure report.

Read the primary source DEInformation exposure and response privacyReviewed 2026-10-02

Root cause

An error-handling configuration could include unintended application data in a response; subsequent review found a broader framework issue.

Demonstrated impact

A copyright-management request could return data fragments not intended for the requester. The award reflected the vendor’s assessment of potential wider impact.

Lessons for review

  • Apply data-minimization rules to error responses as well as successful responses.
  • Review shared exception-handling behavior after an endpoint-level fix.

Award and evidence

USD 65,000Bug Bounty · Vendor Confirmed

Vendor explicitly identifies USD and says the report was paid. Exact transfer date is unknown; this is not the event or program total.

Read the official vendor retrospective and its explicit US-dollar per-report payment. Summaries retain the vendor’s bounded impact statement.

  • Historical case; exact award, settlement and deployment dates are unknown.
  • The source gives a high-level finding, not a complete technical advisory.

Recorded timeline

Published
2020-02-07explicit · Initial page date; a separate May 7, 2020 update is displayed.
Reported
2019-09inferred · September event in the vendor’s 2019 retrospective; the day is unspecified.

Related visual models

Sources and provenance

  1. 2019 Bug Bounty highlights, official Spanish edition Dan Gurfinkel / Facebook · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software