GOOGLE has paused accepting product vulnerability reports under its Open Source Software Vulnerability Reward Program (OSS VRP), effective from 1 October 2026. The move, announced via a post on X and an accompanying GitHub notice, comes after researchers submitted a surge of automated reports that Google says are largely invalid. Supply chain reports remain eligible for rewards, and submissions made before 1 October are not affected.
Google says the pause is temporary and plans an update in the first quarter of 2027 while it reorganises this part of the programme; no date is given for when product vulnerability submissions might resume.
The OSS VRP categorises open-source projects into four tiers and has previously offered monetary rewards for flagship and important product vulnerabilities. The notice confirms that the rewards for product vulnerabilities have been removed entirely, with prior ranges of $3,133.7 to $31,337 for flagship projects and $1,337 to $13,337 for important projects no longer listed.
Supply chain compromises, other security issues, and other tiers retain their existing rewards, while the top two tiers formerly carrying rewards are now shown as none for product vulnerabilities. Google also outlines three avenues for researchers going forward: Cloud VRP for certain Google Cloud repositories, Patch Rewards for patches to covered projects, and other Google reward programmes if a flaw intersects other areas. The company states it will update the rules in 2027 and does not specify when product vulnerability reporting will reopen.