Policy · 6h ago

Google Freezes OSS VRP Product Reports

Google stopped accepting new product-vulnerability reports through its Open Source Vulnerability Rewards Program on Oct. 1, 2026, after automated submissions, mostly invalid AI-generated ones, overwhelmed reviewers. Existing reports stay in scope, and Google says it will revisit the program in Q1 2027.

The pause hits the product side of the program that covers Google open-source projects like Go, Angular, and Protocol Buffers, plus repository settings and related supply-chain components. In plain terms, the intake queue for new product bugs has been shut to new reports, so legitimate findings need a different Google channel or they wait for the program to be reworked.

For researchers and maintainers, the practical change is routing: the normal one-queue path into OSS VRP no longer holds for new product flaws. If a Google open-source project sits on your disclosure path, the exposure now includes delay and detour, not just the bug report itself.

Timeline

Sources

4 sources covering this story

Part of the PlainSec briefing for 2026-10-05

Editions