Google has paused product vulnerability submissions for its Open Source Software Vulnerability Reward Program (OSS VRP) after a flood of invalid, AI-generated reports overwhelmed security engineers and repository maintainers. The company announced the operational freeze in a post on X, directing security researchers toward its other active reward initiatives. Google stated that it will use the downtime to restructure the submission framework, with an official progress update slated for the first quarter of 2027.
What changes and what stays active
The suspension took effect immediately on October 1, though Google outlined specific exceptions to avoid shutting down critical disclosure channels. One of them is that the pause does not affect valid product vulnerability filings logged before October 1. The freeze applies specifically to product vulnerability reports; supply chain disclosures submitted under the OSS VRP remain open.Certain product vulnerability reports tied to Google Cloud repositories that directly impact Cloud products may still be accepted through the separate Google Cloud VRP.
Read Google VRP’s post
PSA for open-source bug huntersWe are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program.Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027.Previously, Linux maintainers reported being completely flooded by bogus Common Vulnerabilities and Exposures (CVE) filings after automated AI hunters drove recorded vulnerabilities to a record high of 2,000 per release. The influx forced the Linux project to drop support for older network drivers.Chipmaker Intel also recently froze its bug bounty program, which offered payouts reaching $100,000 per flaw. While Intel did not cite synthetic submissions as the official cause, industry analysts widely attribute the shutdown to identical AI spam bottlenecks.













Leave a Reply