Bugcrowd's "Request a Response" can expire without a response - Leon Becker's Blog
Skip to content
Leon Becker's Blog<br>Notes on manageable but capable software.
Toggle Menu
On 22 July I got this email from Bugcrowd:
Your request for a response expired without an answer for the following submission:
[title redacted]
Request reason: Duplicate state Request expired on: 22 Jul 2026 20:32:24 (UTC) Requests available: 1 out of 2
I’ve redacted the submission title. This post isn’t about that finding.
By then, I had been waiting three weeks for someone to address the question I had raised about the duplicate verdict.
I had replied in the submission itself first, and waited a week. Then I used Bugcrowd’s official “request a response” feature and waited another 14 days. Nothing in the email addressed the question. It just told me that my request had expired and that I had my slot back.
A few days later, the same thing happened with a second report on a different program.
I may be wrong about both duplicate verdicts. Bugcrowd may have perfectly good evidence that I cannot see. That’s why I asked.
Disputing a duplicate
I’ve had reports marked as duplicates before. On HackerOne, I’ve had quick responses, and when they told me I had duplicated an earlier finding, they were right: I simply hadn’t found something novel. No complaint there.
I don’t think every duplicate verdict is suspicious, and I don’t expect Bugcrowd to show me another researcher’s confidential submission. But Bugcrowd does show some information about the report you’re duplicated against, and in these two cases, what I could see appeared different enough from what I had reported that I thought the decisions deserved another look.
So I replied and explained why. I did not immediately use the escalation mechanism; in both cases I raised the issue in the submission first and gave the triager time to respond. When that produced no answer, I used the feature Bugcrowd provides for exactly this situation: “request a response.”
Both requests eventually expired without one.
For what it’s worth, the same Mattermost program rewarded a different finding of mine. This isn’t about not getting paid, it’s about not getting answered.
Case 1: 21 days
Bugcrowd marked my Mattermost submission as a duplicate on 30 June. Based on the information I could see about the earlier report, I believed it described a different vulnerability.
On 1 July, I replied in the submission and explained why. I also made the limit of my knowledge explicit: if there was an earlier report that actually covered the same issue, I was happy to accept the duplicate. I asked Bugcrowd to check.
Nobody replied. I waited seven days.
On 8 July, I submitted a formal response request with the reason “Duplicate state.” I explained the disagreement again and asked Bugcrowd to verify that the report I had been duplicated against actually covered the same issue. Then I waited another 14 days.
On 22 July, the system marked the request as expired. There was still no response.
From my first objection to the expiry, 21 days had passed, and I still didn’t know whether anyone had even looked at the disagreement.
Case 2: 18 days
The second case, on the ClickHouse program, followed almost the same sequence, but the report was significantly more serious: my reproduction demonstrated a path from a low-privileged user to a persistent administrator account.
Bugcrowd asked me for a complete reproduction package that would work on a default Docker setup: a compose file, a walkthrough, and scripts. I built it and sent it. The next day, the report was triaged and then marked as a duplicate.
Based on the information shown for the earlier report, I believed the two findings involved different access-control failures and would require different fixes. I replied that same day and explained why. I wasn’t asking them to take my word for it. I asked them to compare the two reports, which they could see and I could not, and confirm whether the earlier submission actually covered what I had reported.
Nobody replied. I waited four days.
On 11 July, I used “request a response” and asked again. Then I waited another 14 days.
On 25 July, the request expired. No response. The same email, for the second time:
Your request for a response expired without an answer for the following submission:
Low-privileged user gains admin SQL execution & full data read (+ persistent backdoor) via [mechanism redacted]
Request sent to Bugcrowd
Request reason: Duplicate state Request expired on: 25 Jul 2026 (UTC) Requests available: 2 out of 2
I’ve redacted the part of the title that names the mechanism, because the issue is still unpatched. The impact is quoted as I wrote it in the report.
Note the last line. Both of my request slots are now free, which is the only thing that changed.
From my first objection to the expiry, 18 days had passed. Once again, I had no way of knowing whether anyone had actually compared the...