Google pauses OSS VRP product-vulnerability submissions until 2027
Google has suspended product-vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP), citing invalid AI-generated reports. The pause took effect immediately on October 1.

Key takeaways · 4
- 01
Check whether a finding is a product vulnerability or a supply-chain issue before choosing an OSS VRP submission route.
- 02
Product-vulnerability reports submitted before October 1 are not affected by the suspension.
- 03
A report about a Google Cloud repository may still qualify for Cloud VRP if it affects a Google Cloud product.
- 04
Google encouraged researchers to consider other vulnerability reward programs while it revises this part of OSS VRP.
What Google suspended
Google announced the suspension on October 1 in an official post on X, and it took effect immediately.[1] The affected channel is product-vulnerability submissions to OSS VRP, a program Google describes as rewarding discoveries of vulnerabilities in its open-source projects.[1][2] Google says the program encourages reports about vulnerabilities with the greatest real or potential impact on open-source software in its portfolio.[2] The company attributed the pause to invalid AI-generated reports.[1]
Which reports are still in scope
Google halted the affected product-vulnerability submissions until 2027 and said it would provide an update by the first quarter of that year.[1] The change does not affect product-vulnerability reports submitted before October 1.[1] It also leaves OSS VRP supply-chain reports unaffected.[1] Google may still accept some product-vulnerability reports through Cloud VRP when they concern Google Cloud repositories and affect Google Cloud products.[1] These distinctions matter when researchers decide where to submit a finding.
Why the reporting burden matters
LavX reported that Google engineers and open-source maintainers were overwhelmed by thousands of poorly written reports, including claims about invalid or unexploitable bugs.[1] It said maintainers spent excessive time validating code instead of fixing critical vulnerabilities.[1] LavX attributed the lower effort needed to generate reports to large language models and automated AI bug-hunting scripts.[1] That account gives context for the pause: a high volume of submissions can consume review time even when reports do not identify actionable vulnerabilities.[1]
A wider pressure on bug programs
LavX also reported that Linux maintainers said earlier that month they were overwhelmed by CVE findings as AI bug hunters drove the kernel to a record 2,000 vulnerabilities per release.[1] LavX reported that Intel had also suspended its bug bounty program, which paid up to $100,000 per flaw.[1] However, Intel did not officially confirm AI-generated reports as the reason for its suspension; security experts suspected they contributed, according to LavX.[1] Google encouraged participants to consider other vulnerability reward programs while it works on revising the affected part of OSS VRP.[1]
For security teams and maintainers, the pause narrows one route for reporting product vulnerabilities in Google’s open-source portfolio, while leaving supply-chain reports and some Cloud VRP cases outside the suspension. Researchers should distinguish those categories when routing findings and consider other programs, as Google recommends.
Why it matters
Test yourself on this story — 2 questions.
Create a free account to take the quiz, earn XP, and get a daily session built for your industry.
Take the quizHow this developed
5 October 2026
Google pauses OSS VRP product-vulnerability submissions until 2027