The Kestrel bug bounty program is now public
For two years our bug bounty has been invite-only. Starting today, anyone can report a vulnerability in the Kestrel platform or in the open source frameworks we maintain, and be paid for it.
Scope
The Kestrel dashboard, API and CLI
Edge and serverless runtimes
Our open source image pipeline and router
Rewards
Severity | Reward |
|---|---|
Critical | up to $50,000 |
High | up to $15,000 |
Medium | up to $3,000 |
Safe harbour
Good-faith research that follows the program rules will not be met with legal action.