AI slop submissions force Google to freeze its open-source bug bounty
Google paused new OSS VRP vulnerability reports after invalid AI-generated submissions overwhelmed reviewers.
Google stopped accepting new product vulnerability reports to its Open Source Software Vulnerability Reward Program as of October 1, 2026, after a surge of automated submissions that were mostly invalid. The OSS VRP, launched in 2022, pays for privately reported flaws in Google open-source projects such as Go, Angular, and Protocol Buffers, including repository and supply-chain issues. Reports submitted before the cutoff are unaffected, and some Google Cloud repositories may still be reported through the Cloud VRP. Google said it will update the program in Q1 2027 and pointed researchers to other VRPs or the Patch Rewards Program.
- Google stopped new OSS VRP product-vulnerability reports on October 1, 2026.
- Most automated, AI-generated submissions were invalid and overwhelmed reviewers.
- Reports filed before the cutoff still count; some Cloud VRP reports may be accepted.
- Google promised a program update in Q1 2027 and redirected researchers elsewhere.
Full article338 words · extracted from helpnetsecurity.com · click to collapse
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of invalid, AI-generated submissions swamped the engineers and open source maintainers who review them.

The rules page for Google’s OSS VRP states that “as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP.”
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company wrote in an official X post.
SS VRP is Google’s bug bounty for the open-source software it releases, including projects such as Go, Angular and Protocol Buffers. Launched in 2022, it pays security researchers who find and privately report flaws in that code, as well as in repository settings and supply chain components.
What changed
Reports submitted before October 1 are not affected. The company may also still accept product vulnerability reports through its Cloud VRP for some Google Cloud repositories that impact Cloud products.
“We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” it added.
In the meantime, researchers are asked to submit their findings to other VRP programs or to the Patch Rewards Program, which pays for security improvements to the company’s open source projects. The reward table on the page lists no amounts for product vulnerabilities in any of the program’s four project tiers, which run from OT0 (Flagship) to OT3 (Low-priority).
Under the program’s scope, “any design or implementation issue in Google OSS that causes a product vulnerability substantially affecting the confidentiality or integrity of user data in software builds using Google OSS is also in scope for the program.”
The criteria for accepting these reports depend on the project’s tier and the subcategory of the vulnerability.
Google’s decision comes after months of complaints from open source maintainers and bug bounty programs about a flood of low-quality, AI-assisted vulnerability reports, which Help Net Security covered in May.
Text extracted automatically; images, tables and formatting may be missing. Original: