Google Pauses Open-Source Bug Bounty Program Through 2026
The program’s pause took effect Oct. 1 after a significant rise in automated submissions. Google plans to provide an update in the first quarter of 2027.

Google paused its open-source vulnerability rewards program after a significant rise in automated submissions, the vast majority of which were not valid. The pause took effect Oct. 1, and the company plans to provide an update in the first quarter of 2027.
The Open Source Software Vulnerability Rewards Program paid researchers who found vulnerabilities in Google’s open-source software. Google characterized the increase in automated submissions as significant and said the vast majority were not valid.
During the pause, participants are encouraged to consider Google’s other bug bounty programs. The company’s next stated step is an update in the first quarter of 2027.