British Airways · Vulnerability Disclosure

British Airways Vulnerability Disclosure

Vulnerability disclosure

British Airways operates a public, open-submission Vulnerability Disclosure Programme on HackerOne. It is a VDP, not a bug bounty — no scope is eligible for a monetary award. The programme's wildcard scopes (*.britishairways.com and *.ba.com) cover the NDC Communication Hub at ndc.ba.com, so the API surface described in this repository is in scope for security research even though the API itself is not publicly accessible.

British Airways runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

TravelUnited KingdomAviationAirlineDistributionNDCBookingCorporate TravelAirports
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
{"channel" => "HackerOne", "note" => "\"Vulnerabilities must only be reported via the HackerOne platform. Reports submitted through other channels will not be recognized.\" No security@ address is published.", "url" => "https://hackerone.com/british_airways_vdp"}

Source

Vulnerability Disclosure

british-airways-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
source: https://hackerone.com/british_airways_vdp
description: >-
  British Airways operates a public, open-submission Vulnerability Disclosure Programme on
  HackerOne. It is a VDP, not a bug bounty — no scope is eligible for a monetary award. The
  programme's wildcard scopes (*.britishairways.com and *.ba.com) cover the NDC Communication
  Hub at ndc.ba.com, so the API surface described in this repository is in scope for security
  research even though the API itself is not publicly accessible.
program:
  name: British Airways VDP
  handle: british_airways_vdp
  platform: HackerOne
  url: https://hackerone.com/british_airways_vdp
  state: public_mode
  submission_state: open
  offers_bounties: false
  type: vulnerability-disclosure-programme
policy: https://hackerone.com/british_airways_vdp
contact:
  - channel: HackerOne
    url: https://hackerone.com/british_airways_vdp
    note: >-
      "Vulnerabilities must only be reported via the HackerOne platform. Reports submitted
      through other channels will not be recognized." No security@ address is published.
security_txt: false
public_disclosure_permitted: false
disclosure_terms: >-
  "Do not publicly disclose any details of a vulnerability without explicit written
  authorization from British Airways. Public disclosure is not permitted under this program."
scope:
  in_scope:
    - {type: wildcard, asset: '*.britishairways.com', bounty: false}
    - {type: wildcard, asset: '*.ba.com', bounty: false}
    - {type: url, asset: www.britishairways.com, bounty: false}
    - {type: url, asset: 'http://www.britishairways.com/nx', bounty: false}
    - {type: google_play, asset: com.ba.mobile, bounty: false}
    - {type: apple_store, asset: com.britishairways.BAFlights, bounty: false}
    - {type: other, asset: Digital properties owned, operated, or controlled by British Airways}
  out_of_scope:
    - {type: url, asset: accounts.britishairways.com}
    - {type: url, asset: holiday.britishairways.com}
    - {type: other, asset: Internal systems, employee portals, onboard aircraft systems and avionics, third-party services, and assets on external networks or domains not directly owned or controlled by British Airways}
qualifying:
  - Cross-Site Scripting (XSS)
  - Cross-Site Request Forgery (CSRF)
  - Insecure Direct Object References (IDOR)
  - Authentication or Authorization bypasses
  - Injection (SQL, LDAP, XML, command)
  - Server-Side Code Execution (RCE)
  - Privilege Escalation
  - Directory Traversal
  - Information Disclosure with real-world impact
  - Security Misconfigurations exposing sensitive data
  - Open Redirects with demonstrable impact
non_qualifying:
  - Reports without reproducible steps or a proof-of-concept
  - Clickjacking / UI redressing without impact
  - Logout CSRF
  - Banner disclosure, stack traces or descriptive errors without exploitability
  - Missing Secure/HTTPOnly cookie flags or security headers unless exploitable
  - Outdated SSL/TLS ciphers and classic SSL attacks (BEAST, BREACH)
  - Subdomain takeover without a full proof-of-concept
  - Content spoofing / text injection without an attack vector
  - Denial of Service testing
  - Social engineering of staff, contractors or customers
  - Onboard aircraft systems or avionics
rules_of_engagement:
  - One vulnerability per report unless chaining is required to demonstrate impact
  - Multiple issues from a single root cause are treated as one report
  - Only the first valid submission of a duplicate is triaged
  - Test accounts must be owned by the researcher or explicitly permitted
  - No pivoting from a vulnerability into other systems or services
  - No data exfiltration under any circumstances
  - Employees, service providers and those in a working relationship with BA or its
    subsidiaries may not participate
evidence:
  - source: https://hackerone.com/british_airways_vdp
    kind: hackerone-programme
    fetched: '2026-07-28'
    status: 200
    note: >-
      Programme metadata, 5,381-character policy and 11 structured scopes retrieved from the
      HackerOne public GraphQL API on 2026-07-28.
  - source: /.well-known/security.txt
    kind: absent
    note: No RFC 9116 document on any British Airways host — see well-known/british-airways-well-known.yml.