← All stories
● Covered by 2 sources · 2 reportsMedium impact2 neutral

GitHub Restructures Bug Bounty Program, Reduces Public Payouts by July 2026

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • GitHub introduces a permanent, invite-only VIP bug bounty program.
  • VIP researchers receive higher payouts and direct team access.
  • Public program payouts will be cut by at least 50% starting July 27, 2026.
  • Public payouts will become fixed amounts per severity level.
  • Critical findings in the public program will drop to $10,000 from $20,000-$30,000+.

Program Overhaul

GitHub is implementing significant changes to its bug bounty program, aiming to shift focus from the quantity of submissions to their quality and impact. These adjustments follow a period of reflection on the program's performance and industry trends, as well as an increase in the submission queue.

The restructuring involves the creation of a permanent, invite-only VIP program for researchers who consistently deliver high-quality, high-impact work. This VIP tier will offer higher payouts and closer collaboration with GitHub's security engineering team.

Public Program Changes and Payout Reductions

Effective July 27, 2026, the public bug bounty program will see a reduction in payouts across all severity levels. Payouts for critical findings will decrease from a range of $20,000-$30,000+ to a fixed $10,000. The VIP tier, in contrast, will offer $30,000 or more for critical findings.

The public program will transition from flexible payout ranges to static, fixed payments. For example, low-severity findings will now pay $250 (down from $617-$2,000), medium-severity $2,000 (down from $4,000-$10,000), and high-severity $5,000 (down from $10,000-$20,000). These new rates represent at least a 50% reduction for medium, high, and critical findings, and approximately 59% for low-severity reports compared to the previous minimums.

Rationale Behind the Changes

GitHub states that these changes are intended to reduce 'noise' in the submission queue, allowing the security team to focus on more impactful vulnerabilities. The company emphasizes that the goal is to reward better submissions rather than a higher volume of submissions. Fixed payments are expected to remove uncertainty for researchers and streamline the triage process.

Reports submitted before July 27, 2026, including those currently in GitHub's triage queue, will be processed under the previous payout terms.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

GitHub will reduce public bug bounty payouts by at least 50% across all severity levels starting July 27, 2026, while increasing rewards for its invite-only VIP tier. This change aims to decrease noise in the public program and provide established researchers with higher rewards and direct access to the security engineering team.

GitHub is restructuring its bug bounty program to prioritize quality and impact over the quantity of submissions. This includes introducing a permanent, invite-only VIP program for qualified researchers offering higher payouts and closer collaboration. The public program will also shift to static payouts per severity level to provide clearer expectations for researchers.