Bottom line: AI-generated but substanceless vulnerability reports are overwhelming triage teams so severely that projects like cURL, CycloneDX and Log4j have had to shut down or restrict their bug bounty programs.
Large language models have driven the cost of producing seemingly plausible vulnerability reports to near zero — with the result that triage teams at well-known open-source projects are drowning in a flood of useless submissions. Several projects have already discontinued or drastically curtailed their bug bounty programs as a result.
Daniel Stenberg, maintainer of the open-source tool cURL, discontinued the project’s bug bounty program in January 2026. He cited not budget or capacity constraints, but effective overload from unusable submissions: through 2025, fewer than five percent of reports identified an actual vulnerability. In just the first 21 days of 2026 alone, twenty reports came in — none of them valid. Stenberg described dealing with the flood as psychologically stressful and a waste of time and energy.
cURL is not alone. Django’s security team has also seen a rise in AI-generated reports. The CycloneDX project has shut down its program entirely. At the Apache Software Foundation’s Log4j project, a volunteer team reviewed 67 reports within a few months, with the majority arriving in just the last two months alone. Google has excluded AI-generated submissions from its open-source vulnerability rewards program. GitHub tightened its submission requirements after its own triage teams could no longer reliably distinguish genuine findings from noise, and confirmed that the problem is occurring industry-wide, with individual programs already shut down entirely as a result.
According to the report, the root cause lies in how large language models work: they generate text based on statistical pattern prediction rather than fact-based analysis, producing coherent-sounding but fabricated vulnerability descriptions. This largely eliminates the previously informal quality filter for submissions — the need to understand the codebase, actually reproduce an issue, and document the finding with technical rigor. The cost of producing a professional-looking report drops toward zero, while the effort required for triage stays the same or even increases, since well-formatted AI submissions are harder to identify as obviously useless than the poor-quality false reports common in the past.
For CISOs who run their own bug bounty or vulnerability disclosure programs, or who rely on open-source components covered by such programs, the risk landscape is shifting: rising triage load ties up capacity that would otherwise go toward handling genuine reports, and creates blind spots in areas of their own attack surface previously covered by community testing. Programs should review their submission processes — for example through stricter proof-of-concept requirements, reputation systems for submitters, or targeted pre-filtering — to preserve the functionality of this security mechanism.
Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.