
BuzzFeed
External Program
Submit bugs directly to this organization
BuzzFeed is a cross-platform, global network for news and entertainment that generates seven billion views each month. BuzzFeed creates and distributes content for a global audience and utilizes proprietary technology to continuously test, learn and optimize.
No technology is perfect, and BuzzFeed believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly. By participating in this program, you agree to be bound by these rules.
BuzzFeed, at its sole discretion, may provide rewards to researchers for confirmed and resolved qualifying vulnerability reports.
If we receive more than one report for the same issue, we only reward the first researcher to report a vulnerability. You are responsible for any tax associated with any bounty payment.
You are responsible for complying with any applicable laws. You are not eligible to participate in this program if (i) you are a resident of any OFAC sanctioned country, (ii) you are an employee or immediate family member of an employee of BuzzFeed, Inc., or (iii) you are under 18 years of age. We ask that you:
Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
Please note that public disclosure of a vulnerability prior to resolution will result in disqualification from the program. Any information you receive or collect about BuzzFeed, our affiliates or any of our users, employees or agents in connection with this program (“Confidential Information”) must be kept confidential and only used in connection with this program. You may not use, disclose or distribute any such Confidential Information, including without limitation any information regarding your submission, without BuzzFeed’s prior written consent.
While researching, we kindly ask you to refrain from:
X-XSS-Protection or Content-Security-Policy.target="_blank" and manipulation of window.opener will not be accepted. See related information here. We agree with the assessment: "this class of attacks is inherent to the current design of web browsers and can't be meaningfully mitigated by any single website."BuzzFeed reserves the right to modify the terms of this program or terminate this program at any time. Thank you for helping keep BuzzFeed and our users safe!