OFICIAL Vercel Blog

The Vercel Bug Bounty Program is now publicly available

What happened
Based on Vercel Blog · Sep 24, 2026

Vercel has launched a public bug bounty program on HackerOne, consolidating its private and open-source initiatives to simplify reporting and improve security across its platform.

The Vercel Bug Bounty Program is now publicly available
Vercel Blog — Vercel
Key points
·
Vercel merged private and open-source bug bounty programs into a single public program in 2022
·
All Vercel platform products and open-source projects are now covered under the unified HackerOne program
·
Existing submissions to the prior open-source program will still be reviewed without requiring resubmission

In 2022, Vercel operated a private bug bounty program through HackerOne, collaborating with the platform’s VIP program to refine processes and onboard top researchers. Over time, the company worked to harden security across its platform by addressing thousands of reports and improving its triage and remediation workflows. The private program served as a testing ground for refining internal processes before expanding to a public model.

The new public program merges the private initiative with Vercel’s open-source bounty efforts, creating a unified approach to vulnerability reporting. The company notes that artificial intelligence has increased the volume of both valid and invalid reports, but maintains that public programs still yield valuable findings. Vercel has invested in tooling to filter noise and expedite fixes, ensuring efficient handling of submissions.

All products within the Vercel platform and its open-source projects are now covered under the single public program. Researchers can submit findings directly through the HackerOne platform, with clear guidelines and reproduction steps required for valid reports. The program aims to simplify disclosure by eliminating confusion from multiple reporting channels.

Vercel emphasizes its commitment to fast response times and transparent communication with researchers. Existing submissions to the previous open-source program will still be reviewed, and researchers from the private program will continue to participate without changes. The company also invites security professionals to join its team, highlighting ongoing hiring needs.

Original source → Deals on Clipraptor.com →