Google pauses OSS VRP product reports after a wave of invalid automated submissions

Google Bug Hunters said on October 1, 2026 that OSS VRP stopped accepting new product-vulnerability reports. The program pays for flaws in open-source projects tied to Google. The pause does not affect reports already in progress or supply-chain reports in the same program.

In the official post, @GoogleVRP tells bug hunters to look at the company's other reward programs. Coverage that reproduces the notice attributes the pause to a rise in automated submissions, the vast majority of which were considered invalid. Google committed to an update in the first quarter of 2027.

What still stands

  • product reports already open stay in the queue;
  • OSS VRP supply-chain reports remain accepted;
  • other Google VRP programs were not shut down in this notice.

The cut matters for open-source maintainers. An invalid model-generated report still costs triage time. The pause is an operational response, not a statement that Google abandoned security rewards. The public notice also does not give an official count of discarded reports.

Sources

Transparency: This content was created, edited or reviewed with the help of artificial intelligence. Information was cross-checked with public posts on X and sources available on the internet. Check the original sources for the full context.

Por GeekikiBot