JetBlue · Vulnerability Disclosure

Jetblue Vulnerability Disclosure

Vulnerability disclosure

JetBlue runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

TravelUnited StatesAviationAirlineDistributionNDCGDSBookingLoyalty
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://hackerone.com/jetblue

Source

Vulnerability Disclosure

jetblue-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: https://www.jetblue.com/legal/vulnerability-disclosure-policy
program: JetBlue Vulnerability Disclosure Program
platform: HackerOne
policy:
- https://www.jetblue.com/legal/vulnerability-disclosure-policy
- https://hackerone.com/jetblue
contact:
- https://hackerone.com/jetblue
security_txt: false
security_txt_note: >-
  No RFC 9116 /.well-known/security.txt is served on www.jetblue.com,
  api.jetblue.com or accounts.jetblue.com — the program exists but is not
  machine-discoverable.
anonymous_reports_accepted: true
bug_bounty: unknown
safe_harbor: >-
  "If you make a good faith effort to comply with this policy during your
  security research, we will consider your research to be authorized, and will
  work with you to understand and resolve the issue quickly."
scope:
  in_scope:
  - www.jetblue.com
  - book.jetblue.com
  - checkin.jetblue.com
  - mobile.jetblue.com
  - movil.jetblue.com
  - api.jetblue.com
  - accounts.jetblue.com
  - help.jetblue.com
  - azrest.jetblue.com
  - magnolia.jetblue.com
  - experience.jetblue.com
  out_of_scope:
  - Any other subdomain of jetblue.com
  - All business partner applications and connected services
  prohibited_tests:
  - Network denial of service (DoS / DDoS)
  - Physical security compromises
  - Social engineering
  - Spamming and phishing
  stop_and_report_if_encountered:
  - Personally identifiable information
  - Financial information (credit card or bank account numbers)
  - Proprietary information or trade secrets
  - Any other data not intentionally shared publicly
disclosure:
  coordinated: true
  policy: >-
    JetBlue asks researchers not to share a report publicly before a patch is
    available, may coordinate a simultaneous advisory, permits self-disclosure
    after checking with JetBlue, and will never publish information about the
    researcher without permission.
evidence:
- source: https://www.jetblue.com/legal/vulnerability-disclosure-policy
  kind: vulnerability-disclosure-policy
  status: 200
- source: https://hackerone.com/jetblue
  kind: bug-bounty-platform-program
  status: 200
  note: 'Page title: "JetBlue - Vulnerability Disclosure Program | HackerOne".'
- source: https://legacycms.jetblue.com/public/.rest/jetblue/v4/page/home/legal/vulnerability-disclosure-policy
  kind: cms-content-endpoint
  status: 200
  note: Used only to read the policy copy the JS-rendered page hides.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/jetblue-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.