@foone in Germany, which is infamously backwards and close-minded about i.e. disclosing 0days, you could go to prison for this.
Germany recently sentenced a software engineer to huge fines for cybercrimes, in a years-long trial that destroyed his career, because he found a plaintext password in a file, told the company about that vulnerability, and went public with it when they bitched at him what business he had finding vulnerabilities in their product (a client of theirs had hired him to figure out why his servers were crashing or smth) (and ofc he waited with the going public until the vuln was closed).