Google pauses new product vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after receiving a surge of likely automated, AI-generated reports that contain many invalid entries. The suspension begins on October 1, 2026, and remains in effect until further notice.
Across the outlets, the common theme is that automated submissions overwhelm the review process for open source maintainers and engineers. Google also indicates that the pause is intended to restructure how reports are submitted and handled. Help Net Security and Bleeping Computer both attribute the problem to an increase in AI-generated “spam” or “slop” reports that flood the program, while Times of India focuses more broadly on the volume of invalid submissions.
All reports note that vulnerabilities submitted before October 1 are still accepted, providing continuity for earlier submissions. The differing coverage primarily reflects emphasis: some outlets highlight AI-generated content specifically, while others describe the operational need to adjust the submission framework.