GitHub is implementing significant changes to its bug bounty program, aiming to shift focus from the quantity of submissions to their quality and impact. These adjustments follow a period of reflection on the program's performance and industry trends, as well as an increase in the submission queue.
The restructuring involves the creation of a permanent, invite-only VIP program for researchers who consistently deliver high-quality, high-impact work. This VIP tier will offer higher payouts and closer collaboration with GitHub's security engineering team.
Effective July 27, 2026, the public bug bounty program will see a reduction in payouts across all severity levels. Payouts for critical findings will decrease from a range of $20,000-$30,000+ to a fixed $10,000. The VIP tier, in contrast, will offer $30,000 or more for critical findings.
The public program will transition from flexible payout ranges to static, fixed payments. For example, low-severity findings will now pay $250 (down from $617-$2,000), medium-severity $2,000 (down from $4,000-$10,000), and high-severity $5,000 (down from $10,000-$20,000). These new rates represent at least a 50% reduction for medium, high, and critical findings, and approximately 59% for low-severity reports compared to the previous minimums.
GitHub states that these changes are intended to reduce 'noise' in the submission queue, allowing the security team to focus on more impactful vulnerabilities. The company emphasizes that the goal is to reward better submissions rather than a higher volume of submissions. Fixed payments are expected to remove uncertainty for researchers and streamline the triage process.
Reports submitted before July 27, 2026, including those currently in GitHub's triage queue, will be processed under the previous payout terms.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
GitHub will reduce public bug bounty payouts by at least 50% across all severity levels starting July 27, 2026, while increasing rewards for its invite-only VIP tier. This change aims to decrease noise in the public program and provide established researchers with higher rewards and direct access to the security engineering team.
GitHub is restructuring its bug bounty program to prioritize quality and impact over the quantity of submissions. This includes introducing a permanent, invite-only VIP program for qualified researchers offering higher payouts and closer collaboration. The public program will also shift to static payouts per severity level to provide clearer expectations for researchers.