Dream Sports · Vulnerability Disclosure

Dream Sports Vulnerability Disclosure

Vulnerability disclosure

Dream Sports runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Companysports-technologyfantasy-sportsopen-sourcedeveloper-toolsplatform-engineeringauthenticationopenid-connectoauth2mobilereact-nativedevopsobservabilitytest-managementota-updatesfeature-flagsindiamcpagent-native
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
{"kind" => "email", "note" => "A named individual's @dream11.com address is published in that SECURITY.md. It is deliberately not copied into this artifact — see the enrichment PII guardrail. Read it from the source URL.", "published_at" => "https://github.com/dream-horizon-org/logwise/blob/master/SECURITY.md"}

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
source: >-
  live probes of /.well-known/security.txt and the disclosure paths on every Dream Sports host, plus
  SECURITY.md across the dream-horizon-org repositories
policy:
- https://github.com/dream-horizon-org/logwise/blob/master/SECURITY.md
contact:
- kind: email
  published_at: https://github.com/dream-horizon-org/logwise/blob/master/SECURITY.md
  note: >-
    A named individual's @dream11.com address is published in that SECURITY.md. It is deliberately not
    copied into this artifact — see the enrichment PII guardrail. Read it from the source URL.
program:
  bug_bounty: false
  platforms_checked: [hackerone.com/dream11, bugcrowd.com/dream11]
  platforms_result: both HTTP 404 — no public program on either platform
  rewards: none published
  safe_harbor: not stated
  acknowledgement_target: within 24 hours (stated in the logwise SECURITY.md)
  encrypted_channel: PGP key available on request
  process:
  - Report privately by email; do not open a public issue.
  - Include affected version/commit, reproduction steps or PoC, impact assessment and mitigations.
  - Dream Sports validates, provides status updates, prioritizes the fix, and notes it in release notes.
coverage_gap: >-
  Exactly one of the 108 public dream-horizon-org repositories publishes a SECURITY.md (logwise).
  Guardian — the authentication and authorization platform, the single repository where a disclosure
  route matters most — publishes CONTRIBUTING.md and a MIT license but no security policy. Checkmate,
  Delivr, Odin, DataGen and odin-mcp publish none either.
consumer_program:
  name: Dream11 Responsible Vulnerability Disclosure Program (RVDP)
  url: https://www.dream11.com/security/rvdp
  status: unreachable-at-probe-time
  observed_http_status: 502
  note: >-
    Dream11 publishes an RVDP covering www.dream11.com and its mobile apps; the page is indexed and
    titled "RVDP". Every attempt during this pass (four requests, two path variants, browser
    user-agent) returned HTTP 502 with Dream11's "Server down!" interstitial, so the policy text could
    not be captured. Recorded as a known-but-unverified policy URL rather than as a confirmed hit.
evidence:
- source: https://raw.githubusercontent.com/dream-horizon-org/logwise/HEAD/SECURITY.md
  kind: security-policy
  http_status: 200
  fetched: '2026-08-04'
- source: https://www.dream11.com/security/rvdp
  kind: disclosure-page
  http_status: 502
  fetched: '2026-08-04'
- source: https://api.dream11.com/.well-known/security.txt
  kind: security.txt
  http_status: 418
  fetched: '2026-08-04'
- source: https://www.dreamsports.group/.well-known/security.txt
  kind: security.txt
  http_status: 404
  fetched: '2026-08-04'
- source: https://hackerone.com/dream11
  kind: bug-bounty
  http_status: 404
  fetched: '2026-08-04'
- source: https://bugcrowd.com/dream11
  kind: bug-bounty
  http_status: 404
  fetched: '2026-08-04'