Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers responsible for reviewing them.
The OSS VRP, launched in 2022, rewards security researchers for privately disclosing flaws in Google's open-source projects, including Go, Angular, and Protocol Buffers, as well as issues in repository settings and supply chain components. The program's scope covers design or implementation issues in Google OSS that could lead to product vulnerabilities affecting user data confidentiality or integrity in software builds utilizing Google OSS.
While new product vulnerability reports are no longer being accepted through the OSS VRP, submissions made before October 1, 2026, will still be processed. Google also indicated that it might continue to accept product vulnerability reports for certain Google Cloud repositories that impact Cloud products, through its Cloud VRP.
The company stated it would reformat and work on this aspect of the OSS VRP, committing to provide an update in the first quarter of 2027. In the interim, researchers are advised to submit their findings to other Google VRP programs or to the Patch Rewards Program, which compensates for security enhancements to the company's open-source projects. The reward table on the OSS VRP page currently lists no amounts for product vulnerabilities across any of the program's four project tiers, which range from OT0 (Flagship) to OT3 (Low-priority).
This decision follows months of concerns from open-source maintainers and other bug bounty programs regarding a surge of low-quality, AI-assisted vulnerability reports. Google's official X post confirmed the pause, attributing it to the "significant rise in automated submissions, the vast majority of which are not valid."






