CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3049

As cited

Copy frozen at (site build).

vulnerabilities

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

GitHub is reducing public bug bounty rewards by at least 50 percent across all severity levels starting July 27, 2026, with critical vulnerabilities capped at $10,000 instead of the previous $20,000-$30,000 range. The company is simultaneously creating a VIP tier that offers $30,000 or more for select researchers. Reports submitted before the July 27 cutoff will maintain current payout rates.

Why it matters: Security researchers and bug bounty hunters need to understand the changed incentive structure may reduce motivation for public disclosure and shift participation toward GitHub's invitation-only program, potentially affecting vulnerability discovery rates.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

GitHub is reducing public bug bounty rewards by at least 50 percent across all severity levels starting July 27, 2026, with critical vulnerabilities capped at $10,000 instead of the previous $20,000-$30,000 range. The company is simultaneously creating a VIP tier that offers $30,000 or more for select researchers. Reports submitted before the July 27 cutoff will maintain current payout rates.

Why it matters: Security researchers and bug bounty hunters need to understand the changed incentive structure may reduce motivation for public disclosure and shift participation toward GitHub's invitation-only program, potentially affecting vulnerability discovery rates.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary