I might be missing some context, but I am deeply unimpressed with how Rémi Denis-Courmont chose to handle this. As far as I can tell, Rodger Combs gave a perfectly lucid explanation of a plausible threat model. If this is how the VLC developers typically handle security issues, then I'm unsurprised that the EU has decided to offer a bug bounty.
https://www.zdnet.com/article/eu-to-fund-bug-bounty-programs...