Google pauses open-source bug bounty due to surge in automated reports

Google has temporarily halted its Open Source Software Vulnerability Rewards Program for product-related reports as of October 1, 2026. The company cited a major increase in automated submissions, most of which are invalid, as the reason for the pause. The program is expected to resume with an update in the first quarter of 2027. The open-source project curl experienced a similar issue, with its rate of valid reports plummeting in 2025. Both cases highlight the challenge of triaging a high volume of low-quality automated submissions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in