Google OSS VRP paused 1 October after AI bug-report flood
Google open source vulnerability rewards program AI submissions pause

Google OSS VRP paused 1 October after AI bug-report flood

Google has stopped taking product-vulnerability reports in its Open Source Software Vulnerability Rewards Program. The pause started 1 October 2026. The company blamed a surge of automated submissions, most of them invalid.

What happened

OSS VRP, launched in August 2022, paid from $100 to $31,337 for flaws in Google-maintained open source, including Go, Angular, Bazel, Protocol Buffers, and Fuchsia, plus supply-chain settings such as GitHub Actions and access rules. Google said the pause does not cover supply-chain reports, reports already in the queue, or product reports filed before 1 October.

Researchers can still send patches through the Patch Rewards Program, which pays up to $15,000 for high-impact fixes, and can still report Cloud-impacting issues through Cloud VRP. Google said it will rework this part of OSS VRP and give an update in the first quarter of 2027.

This is not a one-off. Curl shut its HackerOne program in January after the same class of AI-generated reports. Intel removed paid rewards from its Intigriti program in September without a public explanation. Microsoft warned in May that AI-assisted discovery is raising the volume of vulnerability work across the industry.

Who is affected

  • Researchers who used OSS VRP for product bugs in Google open source. That intake is closed until further notice.
  • Maintainers and security teams who triage inbound reports. Invalid AI write-ups now compete with real flaws for the same review time.
  • Anyone consuming a CVE or advisory that exists only as an unverified model output. Volume is up. Confirmation is not.

What to do now

Do not patch, ticket, or brief a client off an AI-written vulnerability report until a human has reproduced it or a vendor has confirmed it. Keep paying attention to supply-chain and Cloud VRP channels, which Google left open. If your own bounty or disclosure inbox is filling with generated reports, add a reproducibility gate before those items reach engineering.

Source: BleepingComputer, quoting Google's Bug Hunters rules page and its public statement. Google halts open-source bug bounty program amid AI spam surge.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-61500: Rejetto HFS admin session forgery, CVSS 9.3
Rejetto HFS Math.random session cookie signing key forgery