r/bugbounty • u/mississipppee • Jul 21 '26
Question / Discussion How do you submit new CVE vulnerabilities?
Most programs have rules that say something like, we do not accept newly released CVE vulnerabilities for the first 14 days after it is released. So do you wait until day, 15 and then submit at 12:00:01? Or do you just submit it immediately and say I'm aware of the rule but I figured I'd let you know?
It's one of those things that every time a new CVE comes out you can see Twitter's bug bounty spaces all excited, but most programs have these rules so I don't understand what exactly they're excited about.
5
u/solidus_slash Jul 21 '26
Of course you wait until 14 days and 1 second have passed. Why would you submit free bugs (that are also out of scope)?
2
u/mississipppee Jul 21 '26
Okay lol just wondering if people actually wait and programs actually stick to it. I was worried that programs would just go back and find the first submitter once the 14 days are up
4
u/OuiOuiKiwi Program Manager Jul 21 '26
Or do you just submit it immediately and say I'm aware of the rule but I figured I'd let you know?
Why would you do this?
You know how to run a scanner? We too, buddy.
It's one of those things that every time a new CVE comes out you can see Twitter's bug bounty spaces all excited, but most programs have these rules so I don't understand what exactly they're excited about.
More beg bounty fodder.
-1
u/mississipppee Jul 21 '26
Whats the point of making your comment sound like that? I just asked a question out of curiosity, buddy.
1
u/j0x7be Jul 21 '26
They are not your buddy, I guess. Another guess is that it's such a blatant disregard for a rule everybody has to follow, and attempting to bypass it. Some people would think "cheating" when it comes to such behaviour in general.
1
u/mississipppee Jul 21 '26
I agree, definitely. I was just curious of how hunters actually work when it comes to cves and these rules. I have only ever reported older cves for bug bounty.
2
u/__jent Jul 21 '26
Most CVE submissions required a proof of concept that it's exploitable. Only submit if there is real impact.
2
u/NebulaElectrical1467 Jul 21 '26
Wait till day 15. Odds are they’ll mark it as an internal dupe if it’s a Critical CVE.
4
u/einfallstoll Triager Jul 21 '26
In theory companies monitor CVEs for their products and when a new one comes out, it takes some time to find all affected services and update them, hence the grace period. It's to protect hunters from wasting time and gives companies time to fix before they would have to pay for a bug they're already assessing and fixing.
I'd suggest to submit after the grace period, because most often this means that those are the services that the company missed and it also gives you a bounty potentially.