Official Google VRP announcement (October 1, 2026, 16:00 UTC):
“We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports.”
Alternatives suggested: other VRP programs, Patch Rewards Program.
Reason: “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”
Commitment: “We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027.”
Scope clarification: Only product vulnerability submissions to Open Source Software Vulnerability Reward Program are paused — not supply-chain reports, not pre-October-1 outstanding reports. Q1 2027 is an update deadline, not a guaranteed reopening date.