Google will no longer accept new reports of vulnerabilities in its own products as part of its Bug Bounty Program for Open Source Software, the OSS VRP, starting October 1, 2026. The software company justifies the move with a significant increase in automated submissions, the vast majority of which, according to its own statement, are invalid.
An update on the regulation is expected to be provided by the company no earlier than the first quarter of 2027.
Automated submissions overwhelm the review team
The Open Source Software Vulnerability Rewards Program (OSS VRP) has been paying bounties for vulnerabilities in Google's own open-source projects such as Angular or Golang since 2022. Depending on the severity and project, the bounties range from $100 to $31,337, and even higher for particularly sensitive projects like Bazel or Fuchsia.
Specifically, the category of product vulnerability reports is now paused. Other submission pathways of the program continue to operate. In a statement on X, the responsible team explains that the step was necessary due to a significant increase in automated submissions, the overwhelming majority of which are not valid.
Until an update, Google refers affected researchers to its other bug bounty programs outside the product defect area, as reported by TechCrunch.
The pause specifically affects reports of design or implementation errors in products. Reports of supply chain attacks are still accepted by Google.
This move follows a tightening of regulations in March 2026, when Google already required a technical proof such as an OSS-Fuzz reproduction or a merged patch for certain reporting categories to focus the review on genuine findings.
Curl and HackerOne paused their own programs
Google is not the only organization adjusting its reporting pathways due to the flood of AI-generated bug reports. The Internet Bug Bounty (IBB) from HackerOne also paused new submissions in the spring of 2026. HackerOne justified the move by stating that AI-assisted research is increasing vulnerability findings faster than development teams can fix them.
Historically, according to HackerOne, about 80 percent of IBB bounties went to new findings and only 20 percent to fixes. This ratio, in their own assessment, no longer fits the current situation.
The open-source project curl reacted even more drastically. It completely ended its paid program at the end of January 2026 and even refrained from reviewing incoming reports from early July to early August 2026.
The rate of confirmed genuine vulnerabilities, according to the project, has fallen from about 15 to below 5 percent – an independently unverified figure. Maintainer Daniel Stenberg sums up the situation for small projects: "It is not in our power to change how these people and their slop machines work." Apple also limited the number of open bug reports in its Feedback Assistant program in June 2026 and imposed a 30-day ban on users with too many invalid reports.
It will be crucial whether Google uses the update in the first quarter of 2027 for a technical pre-filtering instead of permanently suspending the category. Small open-source projects like curl lack the capacity that large platforms are currently building to separate genuine findings from AI false reports.
It remains to be seen whether the funding jointly launched by Google, Anthropic, AWS, Microsoft, and OpenAI in March 2026 for open-source security tools will have an effect in time.




