Here's the write-up of a simple but severe exploit I found in Cloudflare's email forwarding service.
In early July I asked if the report could be disclosed, seeing as things had changed since the bug was originally reported. Cloudflare agreed and the report was then moved to the public program. As to why it was disclosed now rather than in February when the public program launched, that was my fault for not asking earlier.