Doordash · Vulnerability Disclosure

Doordash Vulnerability Disclosure

Vulnerability disclosure

DoorDash runs a public bug bounty program on HackerOne. What it does NOT publish is a security.txt: the RFC 9116 probe returned 404 on the API host and the docs host, and 403 behind Cloudflare's bot interstitial on www.doordash.com, so there is no machine-readable pointer from any DoorDash domain to the program - a researcher or an agent has to already know to look on HackerOne.

Doordash runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

DeliveryLogisticsLast Mile DeliveryOn-DemandFood DeliveryLocal CommerceMarketplaceRestaurantGroceryRetailFulfillmentWebhook
Program: Hackerone

Disclosure Policy

Security Contact

Contact
channelHackerOne
Contact
urlhttps://hackerone.com/doordash

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-17'
method: searched
source: https://hackerone.com/doordash
provider: doordash
description: >-
  DoorDash runs a public bug bounty program on HackerOne. What it does NOT publish is a
  security.txt: the RFC 9116 probe returned 404 on the API host and the docs host, and 403 behind
  Cloudflare's bot interstitial on www.doordash.com, so there is no machine-readable pointer from
  any DoorDash domain to the program - a researcher or an agent has to already know to look on
  HackerOne.
program:
  published: true
  type: bug-bounty
  platform: HackerOne
  url: https://hackerone.com/doordash
  name: DoorDash Bug Bounty Program
  probed: '2026-09-17'
  http_status: 200
  evidence: >-
    og:title "DoorDash - Bug Bounty Program | HackerOne" and og:url https://hackerone.com/doordash
    served in the page head. The program's scope table, bounty ranges, response targets and
    safe-harbor language are rendered client-side and could not be read anonymously, so nothing
    about them is asserted here.
  summary_quoted: >-
    "The DoorDash Bug Bounty Program enlists the help of the hacker community at HackerOne to make
    DoorDash more secure."
security_txt:
  published: false
  probes:
  - url: https://openapi.doordash.com/.well-known/security.txt
    status: 404
  - url: https://developer.doordash.com/.well-known/security.txt
    status: 404
    note: 302 into /en-US/, which returns the Docusaurus 404 HTML shell.
  - url: https://www.doordash.com/.well-known/security.txt
    status: 403
    note: Cloudflare bot interstitial; unresolvable anonymously rather than proven absent.
disclosure_policy:
  page_published: false
  note: >-
    No vulnerability-disclosure or responsible-disclosure page was found on doordash.com or
    developer.doordash.com. The policy of record is the HackerOne program policy.
contact:
  channel: HackerOne
  url: https://hackerone.com/doordash
gaps:
- >-
  No /.well-known/security.txt on any DoorDash host, so the program is discoverable only by
  searching rather than by probing the domain.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/doordash-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.