Google has suspended its Open Source Software Vulnerability Rewards Program (OSS VRP), a vulnerability search initiative that paid researchers for finding flaws in the company’s open-source software. The pause took effect on October 1, 2026. Google blamed a “significant rise” in automated and AI-generated reports, most of which turned out to be invalid.
Google announced the suspension in posts on X and on the program’s website. It said it would provide “an update” in the first quarter of 2027. According to Tom’s Hardware, Google engineers and open-source maintainers had been overwhelmed by reports that were invalid or contained hallucinations.
Why Google Halted OSS VRP
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said. In the meantime, Google is encouraging participants to look at its other bug bounty programs.
As of October 1, 2026, the OSS VRP no longer accepts product vulnerability reports. Some reports involving Google Cloud repositories that affect Cloud products may still be accepted through the Cloud VRP. Flaws in open-source projects closely tied to Cloud or AI products can go to the Cloud VRP or the AI VRP. Researchers can also turn to the Patch Rewards Program, which pays for security improvements to Google’s open-source projects. Reports submitted before October 1 are not affected.
Product vulnerabilities previously covered flaws that substantially affected the confidentiality or integrity of user data. Examples included memory corruption in file format parsers or network protocols, sanitizer failures, path traversal, and insecure defaults or code examples in documentation.
For OT0 and OT1 repositories, memory corruption reports required exact OSS-Fuzz reproduction steps or an already merged patch. Non-memory corruption reports did not need a patch. Google also urged researchers to build OSS-Fuzz integrations for important projects that lacked them before reporting.
How Project Tiers Shape Vulnerability Search Rewards
Repositories fall into four tiers:
- Flagship (OT0) projects are the most sensitive and carry the highest payouts.
- Important (OT1) projects have significant community impact or security criticality. Both OT0 and OT1 are listed at github.com/google/bughunters.
- Standard (OT2) covers active repositories with stable packages on registries such as npm or PyPI. There is no published list for this tier.
- Low-priority (OT3) includes experimental, sample, research, and archived projects. These earn no financial rewards.
Supply chain compromises pay $3,133.7 to $31,337 for OT0, $1,337 to $13,337 for OT1, and $500 to $3,133.7 for OT2. Other security issues, such as leaked write-access credentials or weak passwords on third-party CI systems, earn $1,000 for OT0 and $500 for OT1. OT2 and OT3 projects receive nothing for product vulnerabilities or other security issues.
A reward panel sets final amounts based on security impact alone. It may pay more for clever or wide-reaching bugs and less for those that depend on hypothetical flaws. It typically pays once per root cause, though bonuses of about $1,000 are possible for especially clever findings or well-written reports. Researchers can donate their rewards to charity. Rewards left unclaimed after 12 months go to a charity of Google’s choosing.
Several categories are excluded:
- Issues rooted in downstream integration
- Typosquatting without proof that build artifacts were compromised
- Insecure installation instructions
- Social engineering
- Bugs with negligible impact
Google also asks researchers to avoid DoS attacks, black hat SEO, spam, and high-traffic automated testing tools. Reports go through Google’s vulnerability form and should include a buildable proof of concept, the affected versions, an impact description, and an attack scenario.







































