"a significant rise in automated submissions, the vast majority of which are not valid," Google said on October 1, explaining why it will pause its Open Source Vulnerability Rewards Program until 2027.
Google's OSS VRP: history, scope and payouts
Google launched the Open Source Vulnerability Rewards Program (OSS VRP) in August 2022 to reward researchers who identify vulnerabilities in Google’s open-source software projects. The program covers the latest versions of open-source software hosted in public repositories owned by Google on GitHub and selected repositories on other platforms. It explicitly includes repository configuration settings such as GitHub Actions workflows, access control rules and GitHub application configurations.
Reward amounts under the OSS VRP range from $100 to $31,337 depending on the severity of the reported flaw and the project's importance. Google describes the OSS VRP as one of several bug bounty programs it operates and says the OSS VRP has a relatively narrow focus.
Why Google paused OSS VRP until 2027
On October 1, Google announced a suspension of the OSS VRP "until 2027." The company attributed the pause to "a significant rise in automated submissions," the vast majority of which it said are not valid. Google framed the suspension as an operational response intended to stem the flood of poor or spurious reports driven by automation.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildScope of the suspension and the company's next steps
Google said the suspension will not affect OSS VRP supply-chain reports or any reports already submitted, leaving those workflows intact for now. The company plans to "reformat" the program and expects to provide an update in the first quarter of 2027.
As an interim measure, Google encouraged researchers to "find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program." That routing advice directs submissions that are closely linked to Google Cloud or AI products to other, more specifically focused programs.
Routing: Cloud VRP, AI VRP and the Patch Rewards Program
Google noted that vulnerabilities in open-source projects closely linked to Google Cloud or AI products are redirected to the Google Cloud Vulnerability Reward Program (Cloud VRP) or the AI Vulnerability Reward Program (AI VRP). The company said this allows reports to be routed to teams "best placed to assess and address them." The Patch Rewards Program was also offered as an alternative pathway for researchers seeking to be rewarded for fixes while OSS VRP is paused.
What this means for security researchers, open-source maintainers, and enterprises
- Security researchers: Many who used OSS VRP for direct rewards will need to decide whether to reroute reports to the Cloud VRP, AI VRP or the Patch Rewards Program, or to hold off until the program is reformatted and reopens in or after Q1 2027. Researchers who specialize in automated scanning tools may find their current submission rates unwelcome under the OSS VRP’s revised intake.
- Open-source maintainers: Maintainers of Google-hosted repositories should note that supply-chain reports remain accepted, and existing submissions will be processed. For other types of vulnerability reports, maintainers and contributors should expect routing to different Google programs depending on the project’s linkage to Cloud or AI products.
- Enterprises and procurement leaders: Organizations that relied on OSS VRP as one vector for discovering and motivating fixes to vulnerabilities in Google-held open-source projects will need to track the reformatting timeline and may need to coordinate alternative reporting channels through Cloud VRP, AI VRP, or the Patch Rewards Program during the pause.
The suspension is a blunt response to an operational pressure point: automated, low-quality submissions that overwhelmed a program designed to surface genuinely impactful bugs. Google’s stated path forward is a program "reformat" and an update in the first quarter of 2027, while steering reporters toward other VRP tracks and the Patch Rewards Program in the meantime. Whether that combination of rerouting and redesign will restore the program’s signal-to-noise balance remains a matter the company plans to address publicly early next year.
Source: Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports — Infosecurity Magazine




