Google has temporarily suspended its bug bounty program for open-source software due to a spike in invalid automated submissions. Effective from October 1, 2026, researchers are no longer able to submit vulnerability reports for open-source projects such as Go, Angular, and Protocol Buffers for rewards. However, reports concerning supply chain security issues are still accepted, and those submitted before the cutoff date remain unaffected.
Reasons Behind the Suspension
The decision to pause the program was announced by Google on October 1 through a post on X, citing a significant increase in invalid submissions, many of which were automated. Although Google did not disclose specific figures or confirm the use of AI tools in these submissions, the rise in quantity and lack of quality prompted the temporary halt.
The Open Source Software Vulnerability Reward Program (OSS VRP) has been revised to reflect this change. While the program has not provided a specific timeline for resuming the acceptance of product vulnerability reports, Google has committed to an update by the first quarter of 2027.
Changes in Reward Structure
Prior to the suspension, the program categorized projects into four tiers based on sensitivity, with rewards ranging from $500 to $7,500 for flagship projects and $101 to $3,133.7 for important ones. These rewards have been removed from the OSS VRP rules, although supply chain compromises and other security issues, such as leaked credentials, still retain their reward structure.
Google’s public GitHub repository detailed these changes on September 30, a day before the announcement. The flagship repositories, which include projects like Go, Angular, and Protocol Buffers, and important repositories have specific reward structures for non-product vulnerabilities that remain unchanged.
Alternative Reporting Channels
In light of the suspension, Google has outlined alternative routes for reporting vulnerabilities. The Cloud Vulnerability Reward Program (Cloud VRP) may still accept certain reports affecting Google Cloud products. Additionally, the Patch Rewards Program offers compensation for security patches, provided they are accepted and remain in place for a month.
Researchers are encouraged to explore other Google reward programs that might cover the vulnerabilities they discover. Some projects, like Go, have specific channels for security reports, such as direct email to their security team, while others like Angular direct reports to Google’s Bug Hunters site.
Addressing Report Quality Concerns
The OSS VRP, launched in August 2022, had already implemented stricter proof requirements in March 2026 to enhance report quality. Concerns about AI-generated submissions, which sometimes included fabricated details, prompted these measures. Additionally, the Go project has updated its security policy to discourage unfiltered reports generated by large language models, highlighting the need for thorough review before submission.
As Google reassesses its program, the focus remains on maintaining the integrity and effectiveness of its bug bounty initiatives, ensuring that valid and impactful security vulnerabilities are identified and addressed.
