generated: '2026-07-28' method: searched probe: true scope: parent-group description: >- Jetstar publishes no vulnerability-disclosure policy on any Jetstar-owned host that could be reached: apiblog.jetstar.com answers a catch-all login shell for /.well-known/security.txt, and www.jetstar.com refused every automated client from this environment. The disclosure channel that DOES exist and DOES cover Jetstar is the parent Qantas Group program — its RFC 9116 security.txt states its scope as "Qantas Group digital assets", and Jetstar Airways Pty Limited is a wholly owned Qantas Group subsidiary. Recorded at group scope, not claimed as a Jetstar-hosted policy. policy: - https://www.qantas.com/.well-known/security.txt - https://bugcrowd.com/engagements/qantas-vdp-ess contact: - mailto:qantas-vdp-ess@submit.bugcrowd.com program: name: Qantas Vulnerability Disclosure Engagement platform: Bugcrowd type: vulnerability-disclosure bounty: not published url: https://bugcrowd.com/engagements/qantas-vdp-ess preferred_languages: en canonical: https://www.qantas.com/.well-known/security.txt submission_requirements: - A clear title in the subject line - The affected URL or asset - A detailed description with reproduction steps - Proof of concept that is benign and non-destructive prohibited_activities_published: true evidence: - source: https://www.qantas.com/.well-known/security.txt kind: security.txt status: 200 content_type: text/plain date: '2026-07-28' file: well-known/jetstar-qantas-group-security.txt quote: >- Thank you for your interest in the security of Qantas Group digital assets. If you believe you have identified a security vulnerability in one of our assets, please submit your findings via our Bugcrowd Vulnerability Disclosure Program using the contact address above. - source: https://bugcrowd.com/engagements/qantas-vdp-ess kind: bug-bounty-platform-page status: 200 date: '2026-07-28' note: >- Engagement page resolves; the scope table is client-side rendered so the per-asset list (and therefore explicit inclusion of jetstar.com) could not be read anonymously. Scope is taken from the security.txt statement. negative_findings: - probe: https://apiblog.jetstar.com/.well-known/security.txt status: 200 note: Catch-all "Login - Jetstar API" HTML shell, not a security.txt. - probe: https://www.jetstar.com/.well-known/security.txt status: 0 note: Akamai-fronted; read timed out. Not confirmed absent. - probe: automated security-program sweep (0-working/probe-security-programs.py) result: vdp=none trust=none note: >- The sweep found nothing on Jetstar hosts; the Qantas Group document above was found by widening the probe to the parent group and is recorded with its scope stated. api_partner_contact: note: >- For API-specific incidents (not security research) Jetstar's published partner technical contact is apisupport@jetstar.com, and commercial/booking issues go to sales@jetstar.com.