AI slop submissions force Google to freeze its open-source bug bounty
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of invalid, AI-generated submissions swamped the engineers and open source maintainers who review them.

The rules page for Google’s OSS VRP states that “as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP.”
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company wrote in an official X post.
SS VRP is Google’s bug bounty for the open-source software it releases, including projects such as Go, Angular and Protocol Buffers. Launched in 2022, it pays security researchers who find and privately report flaws in that code, as well as in repository settings and supply chain components.
What changed
Reports submitted before October 1 are not affected. The company may also still accept product vulnerability reports through its Cloud VRP for some Google Cloud repositories that impact Cloud products.
“We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” it added.
In the meantime, researchers are asked to submit their findings to other VRP programs or to the Patch Rewards Program, which pays for security improvements to the company’s open source projects. The reward table on the page lists no amounts for product vulnerabilities in any of the program’s four project tiers, which run from OT0 (Flagship) to OT3 (Low-priority).
Under the program’s scope, “any design or implementation issue in Google OSS that causes a product vulnerability substantially affecting the confidentiality or integrity of user data in software builds using Google OSS is also in scope for the program.”
The criteria for accepting these reports depend on the project’s tier and the subcategory of the vulnerability.
Google’s decision comes after months of complaints from open source maintainers and bug bounty programs about a flood of low-quality, AI-assisted vulnerability reports, which Help Net Security covered in May.