British Airways · Vulnerability Disclosure
British Airways Vulnerability Disclosure
Vulnerability disclosure
British Airways operates a public, open-submission Vulnerability Disclosure Programme on HackerOne. It is a VDP, not a bug bounty — no scope is eligible for a monetary award. The programme's wildcard scopes (*.britishairways.com and *.ba.com) cover the NDC Communication Hub at ndc.ba.com, so the API surface described in this repository is in scope for security research even though the API itself is not publicly accessible.
British Airways runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
TravelUnited KingdomAviationAirlineDistributionNDCBookingCorporate TravelAirports
Program: Hackerone
Disclosure Policy
Security Contact
Contact
{"channel" => "HackerOne", "note" => "\"Vulnerabilities must only be reported via the HackerOne platform. Reports submitted through other channels will not be recognized.\" No security@ address is published.", "url" => "https://hackerone.com/british_airways_vdp"}