Google has stopped taking product-vulnerability reports in its Open Source Software Vulnerability Rewards Program. The pause started 1 October 2026. The company blamed a surge of automated submissions, most of them invalid.
What happened
OSS VRP, launched in August 2022, paid from $100 to $31,337 for flaws in Google-maintained open source, including Go, Angular, Bazel, Protocol Buffers, and Fuchsia, plus supply-chain settings such as GitHub Actions and access rules. Google said the pause does not cover supply-chain reports, reports already in the queue, or product reports filed before 1 October.
Researchers can still send patches through the Patch Rewards Program, which pays up to $15,000 for high-impact fixes, and can still report Cloud-impacting issues through Cloud VRP. Google said it will rework this part of OSS VRP and give an update in the first quarter of 2027.
This is not a one-off. Curl shut its HackerOne program in January after the same class of AI-generated reports. Intel removed paid rewards from its Intigriti program in September without a public explanation. Microsoft warned in May that AI-assisted discovery is raising the volume of vulnerability work across the industry.
Who is affected
- Researchers who used OSS VRP for product bugs in Google open source. That intake is closed until further notice.
- Maintainers and security teams who triage inbound reports. Invalid AI write-ups now compete with real flaws for the same review time.
- Anyone consuming a CVE or advisory that exists only as an unverified model output. Volume is up. Confirmation is not.
What to do now
Do not patch, ticket, or brief a client off an AI-written vulnerability report until a human has reproduced it or a vendor has confirmed it. Keep paying attention to supply-chain and Cloud VRP channels, which Google left open. If your own bounty or disclosure inbox is filling with generated reports, add a reproducibility gate before those items reach engineering.
Source: BleepingComputer, quoting Google's Bug Hunters rules page and its public statement. Google halts open-source bug bounty program amid AI spam surge.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- CVE-2026-61500: Rejetto HFS admin session forgery, CVSS 9.3
- CVE-2026-102489: Zammad session flaw chained to root, due 5 October
- CVE-2026-105215: ZITADEL Login V1 account pre-hijack, CVSS 9.1
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.