TYPO3 Public Bug Bounty Program Discontinued
The public TYPO3 Bug Bounty Program is ending. Security reporting and coordinated disclosure continue unchanged.
Key Takeaways
- The public TYPO3 Bug Bounty Program is discontinued with immediate effect.
- The 2026 Bug Bounty budget is exhausted, and the program has become unsustainable to operate in its current form.
- The TYPO3 Security Team continues to review and coordinate reported vulnerabilities.
- Security advisories, CVEs, and credit for researchers continue as before.
- This announcement supersedes our May 2026 communication that the Bug Bounty Program would continue with a focus on TYPO3 Core and infrastructure.
What's Changing and Why
In May 2026, we announced that financial rewards for extension vulnerability reports would end, while the TYPO3 Bug Bounty Program would continue with a focus on TYPO3 Core and infrastructure. Since then, the situation has changed, and the TYPO3 Security Team has decided to discontinue the public Bug Bounty Program entirely.
There are two reasons for this decision:
- The available Bug Bounty budget for 2026 has been exhausted.
- The program has become increasingly difficult to operate sustainably.
The volume of incoming reports has grown significantly. Many findings are of low-to-medium severity, an increasing number are generated with the help of AI tools, and some of the same issues have been submitted by multiple different reporters. Reviewing, validating, and coordinating these reports requires substantial Security Team capacity.
A security process is only effective when the team has sufficient time to investigate vulnerabilities thoroughly and address issues where they matter most. The current volume of bounty-driven reports increasingly consumes time the Security Team needs for its work on security related topics affecting the TYPO3 ecosystem. Removing the financial incentive is intended to reduce this volume and allow the team to focus its resources accordingly.
There will be no budget for the Bug Bounty Program in the coming years. Funding a program of this kind on a continuous basis is not sustainable for TYPO3.
What Stays the Same
✅ Security vulnerability reporting via the Responsible Disclosure process
✅ Security Team review and coordinated disclosure
✅ Security advisories and CVEs
✅ Credit for researchers reporting valid security issues
What Ends
❌ Financial rewards through the public TYPO3 Bug Bounty Program
Security Reporting Continues
Ending the Bug Bounty Program does not mean ending security reporting.
We remain fully committed to coordinated disclosure and encourage security researchers, developers, and community members to continue reporting potential vulnerabilities to the TYPO3 Security Team. Reports can be submitted as before via security@typo3.org.
The process for handling reported security issues remains in place, including review by the Security Team, coordination where required, publication of security advisories and CVEs, and appropriate credit for researchers.
Join the TYPO3 Security Team
For those with TYPO3 expertise who want to contribute beyond individual vulnerability reports, there is another way to put that knowledge to use: join the TYPO3 Security Team. The team welcomes contributors who want to help strengthen the security of TYPO3 Core and extensions, contributing to the security of the project as a whole. Beyond giving back to the community, working on the team is also a great opportunity to learn. Reviewing real-world vulnerability reports and reasoning through their impact builds a practical, hands-on understanding of web application security that's hard to get any other way.
We would like to thank all security researchers who have contributed to the TYPO3 Bug Bounty Program over the years. Their work has helped identify vulnerabilities and improve the security of TYPO3 and its ecosystem.
Further details on security reporting are available here.
Questions? Reach out at security@typo3.org.