generated: '2026-07-28' method: searched source: https://hackerone.com/british_airways_vdp description: >- British Airways operates a public, open-submission Vulnerability Disclosure Programme on HackerOne. It is a VDP, not a bug bounty — no scope is eligible for a monetary award. The programme's wildcard scopes (*.britishairways.com and *.ba.com) cover the NDC Communication Hub at ndc.ba.com, so the API surface described in this repository is in scope for security research even though the API itself is not publicly accessible. program: name: British Airways VDP handle: british_airways_vdp platform: HackerOne url: https://hackerone.com/british_airways_vdp state: public_mode submission_state: open offers_bounties: false type: vulnerability-disclosure-programme policy: https://hackerone.com/british_airways_vdp contact: - channel: HackerOne url: https://hackerone.com/british_airways_vdp note: >- "Vulnerabilities must only be reported via the HackerOne platform. Reports submitted through other channels will not be recognized." No security@ address is published. security_txt: false public_disclosure_permitted: false disclosure_terms: >- "Do not publicly disclose any details of a vulnerability without explicit written authorization from British Airways. Public disclosure is not permitted under this program." scope: in_scope: - {type: wildcard, asset: '*.britishairways.com', bounty: false} - {type: wildcard, asset: '*.ba.com', bounty: false} - {type: url, asset: www.britishairways.com, bounty: false} - {type: url, asset: 'http://www.britishairways.com/nx', bounty: false} - {type: google_play, asset: com.ba.mobile, bounty: false} - {type: apple_store, asset: com.britishairways.BAFlights, bounty: false} - {type: other, asset: Digital properties owned, operated, or controlled by British Airways} out_of_scope: - {type: url, asset: accounts.britishairways.com} - {type: url, asset: holiday.britishairways.com} - {type: other, asset: Internal systems, employee portals, onboard aircraft systems and avionics, third-party services, and assets on external networks or domains not directly owned or controlled by British Airways} qualifying: - Cross-Site Scripting (XSS) - Cross-Site Request Forgery (CSRF) - Insecure Direct Object References (IDOR) - Authentication or Authorization bypasses - Injection (SQL, LDAP, XML, command) - Server-Side Code Execution (RCE) - Privilege Escalation - Directory Traversal - Information Disclosure with real-world impact - Security Misconfigurations exposing sensitive data - Open Redirects with demonstrable impact non_qualifying: - Reports without reproducible steps or a proof-of-concept - Clickjacking / UI redressing without impact - Logout CSRF - Banner disclosure, stack traces or descriptive errors without exploitability - Missing Secure/HTTPOnly cookie flags or security headers unless exploitable - Outdated SSL/TLS ciphers and classic SSL attacks (BEAST, BREACH) - Subdomain takeover without a full proof-of-concept - Content spoofing / text injection without an attack vector - Denial of Service testing - Social engineering of staff, contractors or customers - Onboard aircraft systems or avionics rules_of_engagement: - One vulnerability per report unless chaining is required to demonstrate impact - Multiple issues from a single root cause are treated as one report - Only the first valid submission of a duplicate is triaged - Test accounts must be owned by the researcher or explicitly permitted - No pivoting from a vulnerability into other systems or services - No data exfiltration under any circumstances - Employees, service providers and those in a working relationship with BA or its subsidiaries may not participate evidence: - source: https://hackerone.com/british_airways_vdp kind: hackerone-programme fetched: '2026-07-28' status: 200 note: >- Programme metadata, 5,381-character policy and 11 structured scopes retrieved from the HackerOne public GraphQL API on 2026-07-28. - source: /.well-known/security.txt kind: absent note: No RFC 9116 document on any British Airways host — see well-known/british-airways-well-known.yml.