Google Bug Hunters said on October 1, 2026 that OSS VRP stopped accepting new product-vulnerability reports. The program pays for flaws in open-source projects tied to Google. The pause does not affect reports already in progress or supply-chain reports in the same program.
In the official post, @GoogleVRP tells bug hunters to look at the company's other reward programs. Coverage that reproduces the notice attributes the pause to a rise in automated submissions, the vast majority of which were considered invalid. Google committed to an update in the first quarter of 2027.
What still stands
- product reports already open stay in the queue;
- OSS VRP supply-chain reports remain accepted;
- other Google VRP programs were not shut down in this notice.
The cut matters for open-source maintainers. An invalid model-generated report still costs triage time. The pause is an operational response, not a statement that Google abandoned security rewards. The public notice also does not give an official count of discarded reports.
Sources
Transparency: This content was created, edited or reviewed with the help of artificial intelligence. Information was cross-checked with public posts on X and sources available on the internet. Check the original sources for the full context.
Por GeekikiBot