Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Uber
Uber HackerOne
2 more reviews needed for a grade
Write a review Claim this company profile

Work at Uber? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 4 Oct 2026.

What it pays, by severity

Critical $11,400 avg 73 reports firm
High $5,742 avg 402 reports firm
Medium $1,021 avg 885 reports firm
Low $300 avg 618 reports firm

$4,503,748 paid to researchers in total, $77,720 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
339
in 90 days
Resolved
2,695
all time, last one yesterday
Participants
1,162
hunters engaged
Response efficiency
62%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 18 days 339–362
4 Sep 339 reports 4 Oct

Response targets it sets itself

First response
3 days
Triage
5 days
Bounty
60 days
Resolution
60 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 45 days (95 snapshots): intake down 41 reports; response efficiency down 13 points; 90-day payout down $7,175.

See how this programme’s report load compares to others →

Reviews

1 published
Hacktivity: Uber (100 disclosed)
★★★★★ positive

Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/uber Disclosed reports analyzed: 100 Bounties: $3,257 avg, $40,000 range, $123,750 total (38 paid) --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bounty data.

via HackerOne reports 100 resubmit yes
Anonymous researcher · Oct 1, 2026 · Share ↗ 0 helpful
0 comments

Log in to comment

Who this program credits

1,205 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 shubs 4,640 157 / 185 85%
2 sicksec 4,452 161 / 312 52%
3 ngalog 3,511 148 / 194 76%
4 wkcaj 2,897 117 / 132 89%
5 kadusantiago 1,759 82 / 133 62%
6 mashoud1122 1,592 62 / 85 73%
7 crusty0 1,567 41 / 79 52%
8 vijay_kumar 1,438 62 / 86 72%
9 fransrosen 1,308 25 / 26 96%
10 anandpingsafe 1,259 59 / 86 69%
11 todayisnew 1,218 58 / 130 45%
12 mersa-v6 1,108 36 / 76 47%
13 akashpawar 1,014 29 / 41 71%
14 cache-money 990 45 / 56 80%
15 psycho_012 953 26 / 98 27%
16 hunt4p1zza 908 42 / 67 63%
17 parth 842 34 / 48 71%
18 junnn 771 13 / 16 81%
19 d0xing 697 23 / 29 79%
20 whoareme 684 20 / 22 91%
21 corb3nik 610 20 / 22 91%
22 rhynorater 602 27 / 41 66%
23 apolo2 593 26 / 63 41%
24 esswhy 590 12 / 16 75%
25 destruction 544 27 / 44 61%

Showing the top 25 of 1,205 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 30 Sep 2026.

Responsiveness
64% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Mar 2016
Scope entries
52 HackerOne’s count

Scope

43 assets
AssetTypeEligibilityMax severity
*.uberinternal.com OTHER ✓ bounty None
*ubereats.com OTHER ✓ bounty None
Recon Data OTHER ✓ bounty None
Uber Assets OTHER ✓ bounty Critical
uber.com URL ✓ bounty None
Show all 43 assets
AssetTypeEligibilityMax severity
*.carnextdoor.com.au URL out None
*.lioncityrentals.com.sg URL out None
*.ot.to URL out None
*.sobi.io URL out None
*.support-uber.com URL out None
*.uber.com.cn URL out None
*.ubercarshare.com OTHER out None
*.uberscoot.us URL out None
*.ubertransit.io URL out None
*.xchangeleasing.com URL out None
*scaledsolutions.uber.com WILDCARD out None
adsacademy.uber.com URL out None
Autocab OTHER out None
bizblog.uber.com URL out None
Car Next Door OTHER out None
Careem OTHER out None
central-beta.uber.com URL out None
Cornershop OTHER out None
Divested Companies OTHER out None
drive.uber.com URL out None
Drizly OTHER out None
eng.uber.com URL out None
et.uber.com URL out None
Fraud Reports OTHER out None
HKTaxi OTHER out None
https://assets.uber.com URL out None
https://brand.uber.com URL out None
love.uber.com URL out None
merchants.ubereats.com URL out None
newsroom.uber.com URL out None
people.uber.com URL out None
Postmates DOWNLOADABLE EXECUTABLES out None
Routematch OTHER out None
scaledsolutions*.uber.com WILDCARD out None
Transplace OTHER out None
uber.com.cn URL out None
uber.onelogin.com URL out None
UT OTHER out None

HackerOne lists 52 scope entries; its public listing groups many assets under one label, so identical entries are shown once.