Netflix
Bug Bounty program
Reward Range
Platform
Added
Scope
Bug Bounty program
Reward Range
Platform
Added
Scope
Last updated Oct 13, 2025
*.nflxext.com
*.nflximg.net
*.nflxso.net
*.nflxvideo.net
*.prod.cloud.netflix.com
*.prod.dradis.netflix.com
*.prod.ftl.netflix.com
api*.netflix.com
beacon.netflix.com
customerevents.netflix.com
help.netflix.com
ichnaea.netflix.com
ir.netflix.com
ir.netflix.net
meechum.netflix.com
netflixinvestor.com
nmtracking.netflix.com
presentationtracking.netflix.com
secure.netflix.com
www.netflix.com
Netflix Mobile Application for Android
Netflix Mobile Application for iOS
Affiliates or entities such as recently acquired companies
Content Authorization Targets
Content authorization vulnerabilities affecting only the in-browser player
Corporate Assets
Low impact, individually exposed Google Docs with no common root cause (see “Publicly accessible Google Document or Drive Links” in the “Corporate Targets” section)
Microsites
Netflix Gaming Target
Open Source - Atlas
Open Source - Consoleme
Open Source - Dispatch
Open Source - Spectator
Open Source - Weep
Open Source - Zuul
Secondary Assets
Set-top-boxes, smart TVs, streaming sticks Out of Scope
Third party websites or systems hosted by non-Netflix entities Out of Scope