AppNexus · Vulnerability Disclosure

Appnexus Vulnerability Disclosure

Vulnerability disclosure

AppNexus runs a coordinated vulnerability disclosure program on Hackerone.

CompanyAdtechAdvertisingProgrammaticAd ExchangeDSPSSPMobile SDKMarketing
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

appnexus-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
source: https://www.microsoft.com/.well-known/security.txt
api: Digital Platform API
provider_hosted: false
ownership_note: >-
  AppNexus/Xandr no longer runs a disclosure program of its own. appnexus.com and
  xandr.com serve no security.txt (see well-known/appnexus-well-known.yml - both domains
  301 to about.ads.microsoft.com, whose SPA answers 200 with an HTML shell for every
  path). Xandr has been a Microsoft product line since the 2022 acquisition, and the
  Microsoft Security Response Center is the disclosure channel that actually covers the
  Xandr / Microsoft Monetize online services. The program below is therefore the PARENT
  company's, recorded as such rather than attributed to an appnexus.com surface.
program:
  name: Microsoft Security Response Center (MSRC)
  operator: Microsoft Corporation
  report_url: https://msrc.microsoft.com/report/vulnerability
  report_url_status: 200
  policy_url: https://www.microsoft.com/en-us/msrc/cvd
  security_txt: https://www.microsoft.com/.well-known/security.txt
  security_txt_status: 200
  security_txt_host: www.microsoft.com
  self_hosted_on_provider_domain: false
bug_bounty:
  present: true
  name: Microsoft Bug Bounty Program
  url: https://www.microsoft.com/en-us/msrc/bounty
  url_status: 200
  platform: self-operated (MSRC), not HackerOne/Bugcrowd/Intigriti
  note: >-
    Microsoft's Online Services bounty scope is the one that would cover the Monetize /
    Invest platform surface. Xandr-specific scope wording is not published separately.
probes:
- url: https://api.appnexus.com/.well-known/security.txt
  status: 404
- url: https://www.appnexus.com/.well-known/security.txt
  status: 301
  resolved_status: 200
  verdict: miss
  reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text
- url: https://www.xandr.com/.well-known/security.txt
  status: 301
  resolved_status: 200
  verdict: miss
  reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text
- url: https://www.microsoft.com/.well-known/security.txt
  status: 200
  verdict: hit
  scope: parent company
- url: https://msrc.microsoft.com/report/vulnerability
  status: 200
  verdict: hit
  scope: parent company
gap:
  finding: >-
    A researcher who finds a flaw in api.appnexus.com has no machine-discoverable route
    to report it from that host. Publishing an RFC 9116 security.txt on api.appnexus.com
    pointing at MSRC would close this with one file.