We appreciate the community's efforts to make the web a safer place. With our vulnerability disclosure program you can safely and responsibly disclose vulnerabilities to us. Vulnerabilities can be sent to
vulnerability@overstock.com and can be encrypted using our
PGP Key. Please include all information related to the vulnerability along with steps to reproduce it, optionally you can include your name and email for potential rewards and possible entry to the Security Hall of Fame if desired. Submissions can also be submitted using the form below.
Responsible disclosure guidelines
We pledge to not seek legal action on any vulnerabilities responsibly disclosed, our guidelines for responsible disclosure are as follows.
- Provide details needed to reproduce the vulnerability
- Make a good faith effort to not breach privacy, destroy data, degrade or interrupt services
- Give us a reasonable amount of time to address any findings
- Do not modify or access data that does not belong to you
We would ask that you please keep all vulnerabilities private and not share or publicize them until we have had a chance to address them.