They tend to react with "either you can show us that this is a real danger or we'll ignore it".
It seems pretty clear that this bug shows something is terribly wrong and probably dangerous. But the reporter might have limits in analyzing the bug, while the company could easily figure out what's going on and fix it.
This is a bit of a Catch-22 situation, as I get the feeling that proving the danger would often involve doing things that bounty programs specifically forbid, such as "Moving beyond “proof of concept” repro steps"[0]. That may be part of the reason why Microsoft got away with such a stingy response to the RCE vulnerability found in Teams by Oskars Vegeris.[1]
[0] https://www.microsoft.com/en-us/msrc/bounty-online-services?...
[1] https://github.com/oskarsve/ms-teams-rce/blob/main/README.md
https://crd.ndl.go.jp/reference/modules/d3ndlcrdentry/index....
I regularly encounter services that does not handle it very well
That's not the issue ... I have not personally tried this or examined it, it looks like you can change the state of the header parser by including interesting characters in your name. I am not sure if this is server-side or client-side. If the problem is server side, there is a chance you could tweak the strings to get interesting results. But trying to prove that this is a serious problem without explicit authorization will likely have adverse consequences for anyone who does, so only people who are already doing shady stuff explore it.