On October 1, 2026, Google temporarily stopped accepting new product-vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP), which handles security issues in Google-related open-source projects. The pause does not affect outstanding reports or OSS VRP supply-chain reports.
Which OSS VRP submissions are paused?
The pause covers new product-vulnerability submissions. Outstanding reports already in progress and reports about supply-chain vulnerabilities remain unaffected.
Why did Google pause these reports?
Google attributed the pause to a significant rise in automated submissions and said the vast majority were invalid.
What did Google say comes next?
Google encouraged researchers with relevant findings to use other Google VRP programs or pursue the Patch Rewards Program. It said it would continue to reformat and work on this part of OSS VRP and provide an update in Q1 2027.