Policy · 6h ago
Google stopped accepting new product-vulnerability reports through its Open Source Vulnerability Rewards Program on Oct. 1, 2026, after automated submissions, mostly invalid AI-generated ones, overwhelmed reviewers. Existing reports stay in scope, and Google says it will revisit the program in Q1 2027.
The pause hits the product side of the program that covers Google open-source projects like Go, Angular, and Protocol Buffers, plus repository settings and related supply-chain components. In plain terms, the intake queue for new product bugs has been shut to new reports, so legitimate findings need a different Google channel or they wait for the program to be reworked.
For researchers and maintainers, the practical change is routing: the normal one-queue path into OSS VRP no longer holds for new product flaws. If a Google open-source project sits on your disclosure path, the exposure now includes delay and detour, not just the bug report itself.
4 sources covering this story
Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports
Google has paused its Open Source Vulnerability Rewards Program due to a flood of AI submissions
Google halts open-source bug bounty program amid AI spam surge
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.
AI slop submissions force Google to freeze its open-source bug bounty - Help Net Security
Google has stopped accepting OSS VRP product vulnerability reports after a surge of invalid, AI-generated submissions overwhelmed reviewers.
AI slop seems to be overwhelming bug bounty programs.
Part of the PlainSec briefing for 2026-10-05