Google Pauses Open-Source Product Bug Reports, Citing Invalid Automated Submissions
Existing submissions and supply-chain reports remain unaffected. Google promises an update in Q1 2027—not a confirmed reopening.
Loading page…
Existing submissions and supply-chain reports remain unaffected. Google promises an update in Q1 2027—not a confirmed reopening.
Listen to this story
Google has paused new product-vulnerability reports to its Open Source Software Vulnerability Reward Program (OSS VRP), leaving researchers without that route for newly found flaws in Google’s released open-source code. Google cited a surge in automated submissions, most of them invalid; reports described maintainers reviewing thousands of AI-generated claims, including flaws that were not exploitable. Other reward channels remain available, and Google says it will provide an update in Q1 2027, but has not set a date to resume submissions.
Launched in 2022, OSS VRP covers projects including Go, Angular and Protocol Buffers.
Reports submitted before October 1, 2026, are unaffected, and supply-chain submissions remain open.
Some flaws in Google Cloud repositories may still qualify through the Cloud VRP if they affect Cloud products.
Security researchers can no longer submit new product-flaw reports to Google’s open-source bug bounty program. The pause took effect October 1, 2026. Google blamed a surge in automated submissions, saying most were invalid, according to TechCrunch. That closes one reporting route for flaws in Google’s publicly released code, rather than shutting down all of its security reward programs.
Launched in 2022, the Open Source Software Vulnerability Reward Program, or OSS VRP, pays researchers who privately report security weaknesses. Its projects include Go, Angular and Protocol Buffers, as Help Net Security explains. The program covers flaws in released code, along with repository settings and supply-chain components.
Product reports concern defects in the software itself: code errors, faulty logic or design problems. The program’s rules include issues that substantially affect the confidentiality or integrity of user data in software built with Google’s open-source code. Acceptance criteria vary by project tier and vulnerability category.
Tom’s Hardware reported that engineers and maintainers were overwhelmed by thousands of AI-generated reports describing invalid or unexploitable flaws. Reviewers spent time checking those claims instead of fixing genuine vulnerabilities.
This pause is due to a significant rise in automated submissions, the vast majority of which are not valid
Google, in a statement quoted by TechCrunch
For now, Google is directing researchers toward its other vulnerability reward programs. It also points to the Patch Rewards Program, which pays for security improvements to Google’s open-source projects. That offers a different route: rewards for improving security, rather than submitting a new product-flaw report to the paused channel.
Google says it will continue to reformat and work on the product-vulnerability part of OSS VRP, with an update promised in the first quarter of 2027. That commitment is to explain the next step, not to resume submissions on a specified date. The future format of the paused reporting channel remains unresolved.
Loading discussion...
Join the conversation
Explain how you would balance reviewer capacity with keeping genuine reports flowing.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.