Google Pauses New Open-Source Vulnerability Reports
Google stopped accepting new product-vulnerability reports to its Open Source Software Vulnerability Rewards Program on October 1, saying a sharp increase in automated submissions had left most reports invalid. The pause does not affect supply-chain reports or submissions made before that date. The program, known as OSS VRP, rewards researchers for identifying security flaws in Google-maintained open-source software. Google announced the change in a program notice and social-media post. It said it is working to reformat the program and expects to provide an update in the first quarter of 2027. It has not said when product-vulnerability submissions might resume or detailed what changes it is considering. Google attributed the pause to the volume of automated reports and the share it said were invalid. The company did not provide figures for the number of submissions, how many were automated, or how many failed its validity criteria. Reports describing engineers and maintainers as overwhelmed have also circulated, but the available information does not quantify the review burden. The restriction is limited to product vulnerabilities submitted through OSS VRP.