Jetstar · Vulnerability Disclosure

Jetstar Vulnerability Disclosure

Vulnerability disclosure

Jetstar publishes no vulnerability-disclosure policy on any Jetstar-owned host that could be reached: apiblog.jetstar.com answers a catch-all login shell for /.well-known/security.txt, and www.jetstar.com refused every automated client from this environment. The disclosure channel that DOES exist and DOES cover Jetstar is the parent Qantas Group program — its RFC 9116 security.txt states its scope as "Qantas Group digital assets", and Jetstar Airways Pty Limited is a wholly owned Qantas Group subsidiary. Recorded at group scope, not claimed as a Jetstar-hosted policy.

Jetstar runs a coordinated vulnerability disclosure program on Bugcrowd. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

TravelAustraliaAviationAirlineLow Cost CarrierDistributionBookingGDSCorporate TravelQantas Group
Program: Bugcrowd security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
mailto:qantas-vdp-ess@submit.bugcrowd.com

Source

Vulnerability Disclosure

jetstar-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
probe: true
scope: parent-group
description: >-
  Jetstar publishes no vulnerability-disclosure policy on any Jetstar-owned host
  that could be reached: apiblog.jetstar.com answers a catch-all login shell for
  /.well-known/security.txt, and www.jetstar.com refused every automated client
  from this environment. The disclosure channel that DOES exist and DOES cover
  Jetstar is the parent Qantas Group program — its RFC 9116 security.txt states
  its scope as "Qantas Group digital assets", and Jetstar Airways Pty Limited is
  a wholly owned Qantas Group subsidiary. Recorded at group scope, not claimed as
  a Jetstar-hosted policy.
policy:
  - https://www.qantas.com/.well-known/security.txt
  - https://bugcrowd.com/engagements/qantas-vdp-ess
contact:
  - mailto:qantas-vdp-ess@submit.bugcrowd.com
program:
  name: Qantas Vulnerability Disclosure Engagement
  platform: Bugcrowd
  type: vulnerability-disclosure
  bounty: not published
  url: https://bugcrowd.com/engagements/qantas-vdp-ess
  preferred_languages: en
  canonical: https://www.qantas.com/.well-known/security.txt
  submission_requirements:
    - A clear title in the subject line
    - The affected URL or asset
    - A detailed description with reproduction steps
    - Proof of concept that is benign and non-destructive
  prohibited_activities_published: true
evidence:
  - source: https://www.qantas.com/.well-known/security.txt
    kind: security.txt
    status: 200
    content_type: text/plain
    date: '2026-07-28'
    file: well-known/jetstar-qantas-group-security.txt
    quote: >-
      Thank you for your interest in the security of Qantas Group digital assets.
      If you believe you have identified a security vulnerability in one of our
      assets, please submit your findings via our Bugcrowd Vulnerability
      Disclosure Program using the contact address above.
  - source: https://bugcrowd.com/engagements/qantas-vdp-ess
    kind: bug-bounty-platform-page
    status: 200
    date: '2026-07-28'
    note: >-
      Engagement page resolves; the scope table is client-side rendered so the
      per-asset list (and therefore explicit inclusion of jetstar.com) could not
      be read anonymously. Scope is taken from the security.txt statement.
negative_findings:
  - probe: https://apiblog.jetstar.com/.well-known/security.txt
    status: 200
    note: Catch-all "Login - Jetstar API" HTML shell, not a security.txt.
  - probe: https://www.jetstar.com/.well-known/security.txt
    status: 0
    note: Akamai-fronted; read timed out. Not confirmed absent.
  - probe: automated security-program sweep (0-working/probe-security-programs.py)
    result: vdp=none trust=none
    note: >-
      The sweep found nothing on Jetstar hosts; the Qantas Group document above
      was found by widening the probe to the parent group and is recorded with
      its scope stated.
api_partner_contact:
  note: >-
    For API-specific incidents (not security research) Jetstar's published
    partner technical contact is apisupport@jetstar.com, and commercial/booking
    issues go to sales@jetstar.com.