Google suspended product vulnerability submissions for its open-source bug bounty program on October 1, 2026, citing a surge in invalid automated reports. The indefinite pause affects core projects like Go and Angular, while supply-chain reporting and other security reward tracks remain active as teams prepare a program update for early 2027.
Google has officially halted product vulnerability reports through its Open Source Software Vulnerability Reward Program. The freeze took effect on October 1, 2026, shutting down a primary channel where external researchers reported security flaws in projects maintained by the company such as Go, Angular, and Protocol Buffers.
According to company statements, the vast majority of these automated filings lack validity. The decision stems from an overwhelming influx of automated submissions.
Google Cuts Bug Rewards And Alters Open Source VRP Rules
The four-year-old OSS VRP supports vulnerability discovery across repositories run by Google-owned GitHub organizations, selected repositories on other platforms, configuration settings like GitHub actions, access control rules, and third-party dependencies.
Payments made under the program ranged from $500 for security issues in Important (OT1) projects to over $30,000 for supply chain compromises in Flagship (OT0) projects. Flagship repositories carry the highest potential payouts, and the program initially launched in August 2022 with rewards ranging from $100 to $31,337, focusing on security flaws with the most significant impact on the software supply chain.

Updates published to the program’s public GitHub rules on September 30 removed those product bounty amounts entirely. Flagship projects saw their listed rewards drop from $500 to $7,500 down to none, while important repositories lost rewards previously valued between $101 and $3,133.7. The third tier, for low-priority projects, has no listed rewards. For supply chain compromises, payouts are set at $3,133.7 to $31,337 for OT0, $1,337 to $13,337 for OT1, and $500 to $3,133.7 for OT2. OT0 projects receive $1,000 and OT1 projects get $500 for other security issues—such as leaked write-access credentials or weak passwords on third-party CI systems—whereas OT2 and OT3 projects are not awarded anything for product vulnerabilities or other security issues. A reward panel sets final amounts based on security impact alone, paying more for clever or wide-reaching bugs and less for those depending on hypothetical flaws, while typically paying once per root cause with bonuses of about $1,000 possible for especially clever findings or well-written reports. Not all reporting channels closed at once. Reports submitted before October 1 are not affected by the change.
Automated AI Slop Floods Open Source Security Programs
Google’s pause reflects a crisis across open-source security ecosystems where generative tools have lowered the barrier for filing bug reports.
Daniel Stenberg, maintainer of the curl command-line utility and library, reported seeing a surge in AI slop bug reports beginning in early 2024. Roughly 5% of bug reports submitted to the project via its HackerOne Bug Bounty Program by mid-2025 proved valid, whereas around 20% appeared to consist strictly of AI slop. Security researchers at Malwarebytes pointed out that while generating a plausible-sounding report has become much cheaper, verifying or debunking it continues to demand intensive human effort. Linux founder Linus Torvalds stated earlier this year that the continued flood of AI reports had made security work almost unmanageable, and Intel appeared to close down a similar program that paid up to $100,000 for bugs.
According to research published in September 2026 by Google’s Threat Intelligence Group (GTIG), the monthly count of disclosed vulnerabilities doubled over the course of that year up to that point, climbing from 5,045 in January to 10,740 in August. The number of vulnerabilities being exploited in the wild also rose rapidly, from an average of 10.5 per month in 2025 to 18 per month. GTIG researchers expect vulnerability discovery and exploitation to continue to grow in the short to medium term. In 2025, Google awarded a record-breaking $17.1 million to more than 700 security researchers, representing a 40% increase from 2024 when it awarded $12 million in total, bringing its total rewards since launching its first VRP in 2010 to over $81.6 million.

Researchers Direct Valid Work To Alternative Channels
While the product vulnerability track remains frozen, Google encourages security researchers to direct valid work toward alternative avenues. Reports can also be submitted to the AI VRP if they involve open-source projects closely tied to Cloud or AI products.
Google committed to reformatting the suspended program and promised an official progress update in the first quarter of 2027.