Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move.
The pause was announced on X on October 1.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said.
Only product vulnerabilities are covered by the pause. According to Google, it has no impact on the program’s supply chain reports or on any pending reports.
“This change does not affect product vulnerabilities submitted before October 1, 2026,” the company noted in an update on the program’s page.
Some product vulnerability reports may still be eligible elsewhere. “For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP,” Google said.
Advertisement. Scroll to continue reading.
Google wants bug...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE