British Airways · Vulnerability Disclosure

British Airways Vulnerability Disclosure

Vulnerability disclosure

British Airways operates a public, open-submission Vulnerability Disclosure Programme on HackerOne. It is a VDP, not a bug bounty — no scope is eligible for a monetary award. The programme's wildcard scopes (*.britishairways.com and *.ba.com) cover the NDC Communication Hub at ndc.ba.com, so the API surface described in this repository is in scope for security research even though the API itself is not publicly accessible.

British Airways runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

TravelUnited KingdomAviationAirlineDistributionNDCBookingCorporate TravelAirports
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
{"channel" => "HackerOne", "note" => "\"Vulnerabilities must only be reported via the HackerOne platform. Reports submitted through other channels will not be recognized.\" No security@ address is published.", "url" => "https://hackerone.com/british_airways_vdp"}

Source

Vulnerability Disclosure

british-airways-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
source: https://hackerone.com/british_airways_vdp
description: >-
  British Airways operates a public, open-submission Vulnerability Disclosure Programme on
  HackerOne. It is a VDP, not a bug bounty — no scope is eligible for a monetary award. The
  programme's wildcard scopes (*.britishairways.com and *.ba.com) cover the NDC Communication
  Hub at ndc.ba.com, so the API surface described in this repository is in scope for security
  research even though the API itself is not publicly accessible.
program:
  name: British Airways VDP
  handle: british_airways_vdp
  platform: HackerOne
  url: https://hackerone.com/british_airways_vdp
  state: public_mode
  submission_state: open
  offers_bounties: false
  type: vulnerability-disclosure-programme
policy: https://hackerone.com/british_airways_vdp
contact:
  - channel: HackerOne
    url: https://hackerone.com/british_airways_vdp
    note: >-
      "Vulnerabilities must only be reported via the HackerOne platform. Reports submitted
      through other channels will not be recognized." No security@ address is published.
security_txt: false
public_disclosure_permitted: false
disclosure_terms: >-
  "Do not publicly disclose any details of a vulnerability without explicit written
  authorization from British Airways. Public disclosure is not permitted under this program."
scope:
  in_scope:
    - {type: wildcard, asset: '*.britishairways.com', bounty: false}
    - {type: wildcard, asset: '*.ba.com', bounty: false}
    - {type: url, asset: www.britishairways.com, bounty: false}
    - {type: url, asset: 'http://www.britishairways.com/nx', bounty: false}
    - {type: google_play, asset: com.ba.mobile, bounty: false}
    - {type: apple_store, asset: com.britishairways.BAFlights, bounty: false}
    - {type: other, asset: Digital properties owned, operated, or controlled by British Airways}
  out_of_scope:
    - {type: url, asset: accounts.britishairways.com}
    - {type: url, asset: holiday.britishairways.com}
    - {type: other, asset: Internal systems, employee portals, onboard aircraft systems and avionics, third-party services, and assets on external networks or domains not directly owned or controlled by British Airways}
qualifying:
  - Cross-Site Scripting (XSS)
  - Cross-Site Request Forgery (CSRF)
  - Insecure Direct Object References (IDOR)
  - Authentication or Authorization bypasses
  - Injection (SQL, LDAP, XML, command)
  - Server-Side Code Execution (RCE)
  - Privilege Escalation
  - Directory Traversal
  - Information Disclosure with real-world impact
  - Security Misconfigurations exposing sensitive data
  - Open Redirects with demonstrable impact
non_qualifying:
  - Reports without reproducible steps or a proof-of-concept
  - Clickjacking / UI redressing without impact
  - Logout CSRF
  - Banner disclosure, stack traces or descriptive errors without exploitability
  - Missing Secure/HTTPOnly cookie flags or security headers unless exploitable
  - Outdated SSL/TLS ciphers and classic SSL attacks (BEAST, BREACH)
  - Subdomain takeover without a full proof-of-concept
  - Content spoofing / text injection without an attack vector
  - Denial of Service testing
  - Social engineering of staff, contractors or customers
  - Onboard aircraft systems or avionics
rules_of_engagement:
  - One vulnerability per report unless chaining is required to demonstrate impact
  - Multiple issues from a single root cause are treated as one report
  - Only the first valid submission of a duplicate is triaged
  - Test accounts must be owned by the researcher or explicitly permitted
  - No pivoting from a vulnerability into other systems or services
  - No data exfiltration under any circumstances
  - Employees, service providers and those in a working relationship with BA or its
    subsidiaries may not participate
evidence:
  - source: https://hackerone.com/british_airways_vdp
    kind: hackerone-programme
    fetched: '2026-07-28'
    status: 200
    note: >-
      Programme metadata, 5,381-character policy and 11 structured scopes retrieved from the
      HackerOne public GraphQL API on 2026-07-28.
  - source: /.well-known/security.txt
    kind: absent
    note: No RFC 9116 document on any British Airways host — see well-known/british-airways-well-known.yml.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/british-airways-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.