$50
- Low-impact XSS
- Low-risk CSRF
- Minor security misconfiguration with limited impact
- Valid security issue with limited exploitability
Hola is committed to protecting the privacy and security of our users. We welcome responsible vulnerability reports and appreciate the efforts of those who help us identify and fix security vulnerabilities.
Submit a vulnerability
This program applies to previously unknown security and privacy vulnerabilities affecting Hola-owned products and services, including:
*Only the latest publicly available versions of Hola products are considered in scope.
Rewards are determined at Hola’s sole discretion based on severity, impact, exploitability, report quality, and whether the issue was previously known.
*Hola may decide to pay higher rewards for unusually severe vulnerabilities or lower rewards for issues with limited likelihood, limited impact, or incomplete proof of concept.
*Duplicate reports are not eligible for a reward. The first report that clearly demonstrates a valid vulnerability will be considered the original report.
*Any reward that remains unclaimed for more than two months may be canceled.
Any design or implementation issue that affects the confidentiality, integrity, or availability of Hola user data, user accounts, or Hola-owned production systems may qualify.
There are several important issues that do not qualify for a bounty. These include specific cases that fall outside the established guidelines and criteria set forth by our bounty program.
All participants must make a good-faith effort to avoid privacy violations, data destruction, service disruption, or degradation of Hola services. Failure to do so may result in disqualification from the program.
Reports should be submitted in English and include the following sections:
We support responsible security research conducted in good faith. If you comply with this policy, we will not initiate legal action against you for your research. To remain eligible, you must:
Please do not publicly disclose the vulnerability until Hola has completed its investigation and remediation.
We aim to:
Bounty payments are subject to the following restrictions:
We appreciate the security research community’s help in keeping Hola safe. Responsible disclosure helps us protect our users, improve our products, and maintain trust.
Submit a vulnerability