Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software.
The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are not affected.
Google called the stop temporary in a post on X on October 1 and said it was due to “a significant rise in automated submissions, the vast majority of which are not valid.”
The post gave no figures. It did not say whether the submissions were produced with AI tools.
The rules of the program, called the Open Source Software Vulnerability Reward Program (OSS VRP), now carry a notice of the stop. It commits Google to an update in the first quarter of 2027 while it reworks this part of the program.
Neither the post nor the notice gives a date for accepting product vulnerability reports again.
Under the rules, a product vulnerability is a design or implementation flaw in Google’s open source software. It must substantially affect the confidentiality or integrity of user data in software built with that code. Examples include memory corruption in file format parsers and path traversal.


Leave a Reply