GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Overview
GitHub is making significant changes to its public bug bounty program, set to take effect on July 27, 2026. Starting then, payouts for reported vulnerabilities will be reduced by at least 50% across all severity levels. For critical issues, the reward will drop from a range of $20,000 to $30,000+ down to a fixed $10,000. However, GitHub will also introduce a VIP tier that offers payouts of $30,000 or more for select researchers. Reports submitted before the cutoff date will still qualify for the existing payout structure. This move raises concerns about how it might impact the motivation of security researchers to report vulnerabilities, as lower rewards could discourage participation in the program.
Key Takeaways
- Affected Systems: GitHub's public bug bounty program
- Timeline: Disclosed on October 2023
Original Article Summary
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, including those already in GitHub's growing triage queue, will retain the previous payout terms. GitHub said the
Impact
GitHub's public bug bounty program
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on October 2023
Remediation
Not specified
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Critical.