GitHub Slashes Public Bug Bounty Rewards Starting July 2026
GitHub is cutting public bug bounty payouts by up to 50%, shifting top rewards to an invite-only VIP program. The move affects all severity levels, with critical reports now capped at $10,000.
TL;DR
- Starting July 27, 2026, GitHub reduces public bug bounty payouts across all severity levels.
- Critical vulnerability rewards drop from $20,000–$30,000+ to a flat $10,000.
- Higher payouts ($30,000+) moved exclusively to a permanent VIP invite-only tier.
- Reports submitted before the cutoff retain previous reward structures.
- The change may impact researcher participation in GitHub’s public security program.
In a significant shift for its security community, GitHub has announced major cuts to its public bug bounty program rewards beginning July 27, 2026. The new structure halves payouts across all vulnerability severity levels, with critical findings now capped at $10,000—down from previous ranges of $20,000 to over $30,000.
To offset these reductions, GitHub is expanding its invite-only VIP bug bounty tier, which will continue offering rewards of $30,000 or more. While existing submissions filed prior to the change will maintain their original payout terms, the decision raises concerns among public researchers about reduced incentives and potential barriers to entry.
Key Changes to GitHub’s Bug Bounty Program
- Public payouts for critical vulnerabilities decrease from $20,000–$30,000+ to a fixed $10,000.
- All lower severity categories also see at least a 50% reduction in reward amounts.
- Rewards above $30,000 are now restricted to an exclusive, invite-only VIP program.
- Triaged reports submitted before July 27, 2026, remain eligible for previous payment levels.
Implications for Security Researchers
- Reduced financial incentive could discourage independent researchers from targeting GitHub.
- Shift toward VIP-only high rewards may favor established or well-connected researchers.
- Community concerns focus on accessibility and transparency in vulnerability disclosure programs.
- Other platforms may need to evaluate their own bounty structures in response to GitHub’s changes.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.