What Google Paused And What Stays Open

Google said on X on 1 October 2026 that it is temporarily no longer accepting product vulnerability submissions to its Open Source Software Vulnerability Reward Program. It gave one reason: a significant rise in automated submissions, the vast majority of which are not valid.

ScopeStatus after 1 October
New OSS VRP product vulnerability reportsNot accepted
OSS VRP supply chain reportsStill accepted
Reports already filedUnaffected
Some Google Cloud repos, via the Cloud VRPMay still be accepted
Alternatives Google namesOther VRPs and the Patch Rewards Program
Next update from GoogleFirst quarter of 2027

Tom's Hardware adds that the suspension took effect the day it was announced and does not touch product vulnerabilities submitted before that date. It says Google may still take product reports through the Cloud VRP for some Google Cloud repos that affect Google Cloud products.

Google says it will keep reformatting this part of the programme and committed to an update in Q1 2027. That is a promise of news, not of a reopening date.

Why Volume Beat Validity

Tom's Hardware describes the mechanism. OSS VRP product reports cover code defects, logic flaws and design bugs in Google's public repositories, work that used to be painstaking and skilled, until large language models and automated bug-hunting scripts nearly eliminated the cost and effort of filing.

The cost did not disappear, it moved to the receiving side. Tom's Hardware reports that Google engineers and open-source maintainers were reportedly overwhelmed by thousands of poorly written reports of invalid or unexploitable bugs, and spent time validating code instead of fixing real, critical vulnerabilities.

It also points to similar cases: Linux maintainers said they were completely overwhelmed by CVE finds after AI bug hunters pushed the kernel to a record 2,000 vulnerabilities per release, and Intel suspended a bounty that paid up to $100,000 per flaw. Intel did not confirm AI reports as the reason, and Tom's Hardware says only that experts suspect it.

What Google Has Not Said

Google gave no count of reports received or of the share that were valid. Its post says only that automated submissions rose significantly and that the vast majority are not valid, and the figure of thousands comes from Tom's Hardware's reporting, not from Google.

Nor has Google said what the reformatted programme will look like. A commitment to an update in Q1 2027 means researchers who relied on OSS VRP rewards face at least three months, counting from 1 October, without that lane, our arithmetic from the two dates.

The routes Google names are other reward programmes and the Patch Rewards Program. It did not say whether product reports that are valid will be handled somewhere else, and Tom's Hardware reports only the narrow Cloud VRP exception.

What To Do With Your Own Intake

Split intake by report type, as Google did. It paused product vulnerability reports and kept supply chain reports open, which shows a flood can be closed in one lane without shutting the whole programme.

Put the cost of proof on the sender. Ask in the template for a working reproduction and a stated impact, and close reports without them untriaged. Track the share of reports that turn out valid and the hours each valid one costs, so the point at which you pause is a number you chose in advance.

Tell reporters what happens to reports already in the queue, where to go instead and when you will update them. Google did all three, and an intake that cannot validate as fast as it receives will have to close a lane anyway, so choose which one yourself.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.