bayria.com / dev { tunnel: none · direct } ip 216.73.216.236 session: guest v0 · dev ↗ Status

BUG BOUNTY · 4 TIERS

Break it. Get paid.

Critical
$25,000
Pre-auth RCE on tunnel servers. Cleartext recovery of in-transit user traffic. Vault key disclosure across accounts.
High
$8,000
Auth bypass on account portal. Cross-account data read in Drive. Bypass of lawful-intercept dual-key admin authorisation.
Medium
$2,000
Stored XSS in account portal. Prediction of session tokens. CSRF on billing endpoints.
Low
$400
Reflected XSS on marketing surfaces. Disclosure of internal hostnames. SSRF that does not pivot.

Scope.

✓ In scope

*.bayria.com
in scope
iOS / macOS / Windows / Linux client binaries
in scope
github.com/bayria-org/* releases
in scope
Tunnel POPs · pop-*.bayria.systems
in scope

✕ Out of scope

status.bayria.com
rate-limited public probes; report only logic flaws
Third-party SaaS we use (Stripe, Postmark)
report to them
Social engineering against employees
not eligible

Hall of fame.

2026 H1

@anvilbones
Tunnel handshake replay across regions
$25,000
@kira_q
Drive · cross-account share link forgery
$8,000
@rhys.olive
Account portal · OAuth callback open redirect
$8,000
@tn3-anon
Stored XSS in vault note rendering
$2,000
@vitr-1
CSRF on plan-change endpoint
$2,000
@still-meadow
Reflected XSS on /help search
$400