Google OSS VRP pauses product bug reports over AI slop
Google's OSS VRP stopped taking product bug reports on October 1 after a flood of AI-generated invalid reports. Here is how to triage your own inbox.
Google has stopped taking new product vulnerability reports in its OSS VRP, the bug bounty for Google's open-source projects. The reason: too many AI-generated reports that look real and are not. If Google cannot keep up with the triage, a five-person software team will not either. You need a plan for your own security inbox before the same flood finds you.
What actually happened
The Google VRP account posted the notice on X: Google is "temporarily no longer accepting OSS VRP product vulnerability submissions." Tom's Hardware reports that the pause started October 1, 2026, after invalid AI-generated reports buried engineers and maintainers.
The pause is narrower than the headlines:
- Still open: OSS VRP supply chain reports (compromised build pipelines, tampered packages).
- Still processed: reports filed before October 1.
- Redirected: product bugs in some Google Cloud repositories can go to the Cloud VRP instead.
- Next step: Google says it will give an update on the restructured program by Q1 2027.
This is not the first program to break under the load. We wrote about GitHub cutting its bug bounty scope and Apple capping bug reports for the same reason.
Why it matters for your business
Triage is the real cost of AI slop. A script can point a model at a public repo and produce a report with a CVSS score, a "proof of concept," and confident prose in minutes. Reading it and proving it is wrong takes a person an hour. The attacker side scales. The defender side does not.
Your security@ address is a target too. If you publish a plugin, a Shopify app, an API, or an open-source package, you will get these reports. Some come with a request for a "bounty." Most are noise. A few are real, and those are the ones you cannot afford to miss in the pile.
Write the filter before you need it. Require a reproducible proof of concept against a current version. Require the affected file and line. Reject reports that only quote a scanner or a model. Keep a short template reply for invalid reports so a person spends minutes, not hours.
Supply chain still gets priority, and so should yours. Google kept supply chain reports open for a reason. A tampered dependency hits everyone downstream. Pin versions, review lockfile changes, and watch your build pipeline first.
Key takeaways
- Google's OSS VRP stopped taking product vulnerability reports on October 1, 2026
- Supply chain reports and reports filed before October 1 are still handled
- Google expects to announce the restructured program by Q1 2027
- Publish a disclosure policy that requires a reproducible proof of concept
- Keep a template reply for invalid reports and protect your supply chain first
Shipping code that strangers can file reports against? We set up the disclosure policy, the triage workflow, and the dependency controls so a real bug gets found fast and the noise gets closed fast. See what we build or tell us what you ship.
Sources: Google VRP on X, Tom's Hardware.
- #google-oss-vrp
- #bug-bounty
- #ai-slop
- #vulnerability-disclosure
- #open-source
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Zammad CVE-2026-102489 on CISA KEV: patch your helpdesk
CISA added two exploited Zammad flaws to KEV. Chained, they turn a hijacked session into root on your helpdesk server. Upgrade to Zammad 7.2.0 and check for compromise.
Read itSC WordPress backdoor rebuilds itself: cleanup order matters
Sucuri found the SC WordPress backdoor hiding in 8 files, the database and shared memory. Delete in the wrong order and it rewrites itself in seconds.
Read it