Google paused new product-vulnerability submissions to its Open Source Software Vulnerability Reward Program on October 1, 2026, after a surge of mostly invalid automated and AI-generated reports overwhelmed security engineers and maintainers, with an update promised for the first quarter of 2027.
The program rewards researchers who uncover security flaws in Google-backed open-source projects, including major repositories such as Go, Angular and Bazel. Google said the recent submissions frequently included incorrect technical claims, invented exploit paths or vulnerabilities that could not be reached or posed little real-world risk. The company had already tightened its rules in March 2026 by requiring stronger evidence for some reports, including OSS-Fuzz reproductions or merged patches.
The suspension applies to new product-vulnerability reports, rather than ending the entire program. Reports submitted before October 1 will continue to be handled, while supply-chain submissions remain eligible. Google is directing researchers to other vulnerability-reward programs, including its Cloud and Patch Rewards programs, while it redesigns the OSS process.
The decision highlights a growing challenge for bug-bounty programs: generative AI can produce convincing security reports quickly, but humans still must verify every claim.