www.infosecurity-magazine.com 5 Oct 2026, 10:30 UTC

Google Pauses Open Source Bug Bounty Programme Until 2027

CyberSIXT Evidence Panel Source marked as original reporting

GOOGLE has halted its Open Source Vulnerability Rewards Program (OSS VRP) until 2027, after noting a surge in automated submissions that are largely invalid. The pause was announced via a social media post dated 1 October 2026. The move aims to curb the flood of AI-generated or non-genuine reports while Google refines the programme.

Launched in August 2022, the OSS VRP rewards researchers for identifying vulnerabilities in Google’s open‑source software projects hosted in public repositories on GitHub and other platforms. The programme also covers repository configuration settings such as GitHub Actions workflows and access controls. Rewards range from $100 up to $31,337, depending on severity and the project’s importance.

Vulnerabilities in Google’s open-source projects that relate to Google Cloud or AI products are funnelled to the Cloud VRP or AI VRP for assessment. Google states that the suspension will not affect supply‑chain reports or any submissions already received, and it plans a reformatted OSS VRP with an update expected in the first quarter of 2027. In the meantime, researchers are encouraged to submit relevant findings to alternate VRPs or to the Patch Rewards Programme.

View full article

Article by CyberSIXT