Taboola · Vulnerability Disclosure

Taboola Vulnerability Disclosure

Vulnerability disclosure

Taboola publishes a full, standalone Vulnerability Disclosure Policy — not a paragraph inside the privacy policy, which is what a prior round had recorded. It carries a brand promise, an explicit scope list, a safe-harbour legal posture, a named reporting mailbox, a stated response SLA and a discretionary reward program. There is no HackerOne or Bugcrowd program (both /taboola pages return 404) and no security.txt is served on any Taboola host.

Taboola runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

AdvertisingNative AdvertisingDiscoveryPerformance MarketingAdTechRealizeBackstageRecommendationPublishersProgrammatic
Program: Hackerone

Disclosure Policy

Security Contact

Contact
bountyprogram@taboola.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://policies.taboola.com/vulnerability-disclosure-policy/
provider: Taboola
providerId: taboola
description: |-
  Taboola publishes a full, standalone Vulnerability Disclosure Policy — not a paragraph
  inside the privacy policy, which is what a prior round had recorded. It carries a brand
  promise, an explicit scope list, a safe-harbour legal posture, a named reporting mailbox,
  a stated response SLA and a discretionary reward program. There is no HackerOne or
  Bugcrowd program (both /taboola pages return 404) and no security.txt is served on any
  Taboola host.
policy_url: https://policies.taboola.com/vulnerability-disclosure-policy/
last_updated: '2023-07-26'
contact: bountyprogram@taboola.com
postal: Taboola, Inc., 16 Madison Square West, 7th fl., New York, New York 10010

x-evidence:
  - fetched: '2026-08-13'
    url: https://policies.taboola.com/vulnerability-disclosure-policy/
    http_status: 200
    note: Reached via https://policies.taboola.com/vulnerability-disclosure/ (302).
  - fetched: '2026-08-13'
    url: https://hackerone.com/taboola
    http_status: 404
  - fetched: '2026-08-13'
    url: https://bugcrowd.com/taboola
    http_status: 404
  - fetched: '2026-08-13'
    url: https://www.taboola.com/.well-known/security.txt
    http_status: 404
  - fetched: '2026-08-13'
    url: https://developers.taboola.com/.well-known/security.txt
    http_status: 200
    note: Soft 200 — the ReadMe SPA HTML shell, not a security.txt document.

scope:
  in_scope:
    - www.taboola.com and affiliate/subsidiary websites displaying the Taboola Privacy Policy
    - Connexity
    - Skimlinks
    - Gravity R&D
    - Content Discovery Platform — feeds, widgets, analytics tools and other technical applications served on third-party sites
    - Taboola News (including the Start line of products)
  not_named:
    - the Backstage API (backstage.taboola.com)
    - the Realize MCP server (mcp.realize.com)
  note: >-
    The scope list is written around consumer/publisher-facing web surfaces. Neither
    developer API host is named explicitly, though "other technical applications" is broad
    enough to cover them.

safe_harbour: true
legal_posture: >-
  Taboola commits not to pursue legal action against researchers who test within scope,
  cause no harm, follow local law, and hold disclosure until a mutually agreed timeframe
  expires. Explicitly authorizes reverse engineering and circumventing protective measures
  for the purpose of improving the Services.

response_sla:
  first_response: 10 business days
  commitments:
    - expected remediation timeline provided after triage
    - notification at each stage of review
    - recognition after validation and resolution

rewards:
  offered: discretionary
  program_type: none — no third-party bug bounty platform
  note: >-
    "We may reward submissions" at Taboola's sole discretion. The reporting mailbox is
    named bountyprogram@taboola.com, but no scoped bounty table, severity tiers or payout
    range is published.

reporting_requirements:
  - date the vulnerability was tested for and found
  - steps to reproduce
  - supporting screenshots in JPEG (when relevant)
  - short description of potential impact
  - a signed affirmative statement agreeing to the Policy and Terms of Use

related:
  security_contact_in_dns:
    record: CAA iodef
    value: 'mailto:security@taboola.com'
    source: security/taboola-domain-security.yml
    note: >-
      A second security address exists in DNS. The published policy directs reports to
      bountyprogram@taboola.com; the CAA iodef address is for certificate-issuance
      incidents.
  trust_center: security/taboola-trust-center.yml