Cloudflare opens $3,000 bug bounty programme to the public

A person coding on a laptop computer

Cloudflare, a provider of web infrastructure and security services, has announced the launch of its public bug bounty programme.

Bug hunters and security researchers can now report vulnerabilities found in Cloudflare products as part of the company's latest programme, which is hosted on HackerOne.

A private bounty program was previously launched in 2018, following a vulnerability disclosure programme in 2014. The company paid $211,512 in bounties during the lifetime of this programme, with 292 out of the 430 reports receiving a reward.

Rewards for Cloudflare's latest programme vary with the severity of the vulnerability. Each security flaw is assigned a severity rating based on the Common Vulnerability Scoring Standard (CVSS) version 3.

There is a $3,000 payment for a critical vulnerability report, while high, medium, and low vulnerabilities are worth $1,000, $500, and $250, respectively. However, rewards vary for secondary and other targets.

As a way to make vulnerability research easier, Cloudflare also developed a sandbox called CumulusFire, which provides a standardised playground for researchers to test their exploits. The sandbox will also assist Cloudflare’s security teams in reproducing potential exploits for analysis.

“CumulusFire has already helped us address the constant trickle of reports in which researchers would configure their origin server in an obviously insecure way, beyond default or expected settings, and then report that Cloudflare’s WAF does not block an attack. By policy, we will now only consider WAF bypasses a vulnerability if it is reproducible on CumulusFire,” explained Cloudflare.

A good place to start is to refer to the documentation on Cloudflare's developer and API portals, the Learning Center, and its support forums.

The firm also aims to add additional documentation, testing platforms, and a way for researchers to interact with its security teams to ensure submissions are valid.

Read more
Microsoft Copilot logo and branding pictured on a smartphone screen, with smartphone placed on top of a laptop keyboard.
Microsoft is increasing payouts for its Copilot bug bounty program
Cloudflare webiste
Everything you need to know about Cloudflare
Cloud storage concept and cloud computing concept. Digital technology background with Cloud 3D icon
Nakivo backup flaw still present on some systems months after firms’ ‘silent patch’, researchers claim
Microsoft logo and branding pictured on a wall with silhouettes in foreground.
Everything you need to know about the Microsoft Power Pages vulnerability
ServiceNow signage pictured during the Singapore FinTech Festival in Singapore, on Wednesday, Nov. 15, 2023.
Old ServiceNow vulnerabilities could cause havoc for unpatched customers
Female developer carrying out software security flaw remediation tasks on desktop computer in dimly-lit room with two monitors.
Software security debt is spiraling out of control – remediation times have surged 47% in the last five years, and it’s pushing teams to breaking point
Latest in Cloud Security
AI chatbot text dialogue boxes in difference colours above a digital circuit board with lines of light emanating from it
Enterprise AI is surging, but is security keeping up?
Cloud storage concept image showing digitized cloud symbol with data flows.
AI is putting your cloud workloads at risk
Logo of Google Cloud, which recently announced the Wiz acquisition, pictured at Mobile World Congress 2025 in Barcelona, Spain.
The Wiz acquisition stakes Google's claim as the go-to hyperscaler for cloud security – now it’s up to AWS and industry vendors to react
Wiz logo pictured on a laptop screen.
Google confirms Wiz acquisition in record-breaking $32 billion deal
A multicolored, CGI padlock set against blue and yellow glowing slabs representing SWG and next-gen SWG in a cloud environment.
What is a secure web gateway (SWG) and next-gen SWG?
Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities.
Surging CNAPP investment is a big opportunity for the channel
Latest in News
Ransomware concept image showing a warning symbol in red with binary code in background.
Healthcare systems are rife with exploits — and ransomware gangs have noticed
Application security concept image showing a digitized padlock placed upon a digital platform.
ESET looks to ‘empower’ partners with cybersecurity portfolio updates
Databricks logo and branding pictured on a MacBook Pro screen.
Databricks and Anthropic are teaming up on agentic AI development – here’s what it means for customers
Dell Technologies logo and branding pictured at the company's stall at Mobile World Congress (MWC) in Barcelona, Spain.
Scale of Dell job cuts laid bare as firm sheds 10% of staff in a year
Male employee sitting at a desk working on a laptop with earphones in and books scattered on desk.
Employees want purpose, and they’re willing to quit to find it – upskilling, career growth, and work-life balance have shifted priorities for workers
NHS logo displayed on a smartphone screen in white lettering on a blue background.
NHS supplier hit with £3m fine for security failings that led to attack