Think of a brick-and-mortar analogy. You queue up at airport security, you go through, and you notice that their procedures are such that one COULD bring a banned item through and potentially not get spotted. You inform the appropriate authorities that you think there might be a weakness, and you say how and why.
This is probably not going to get you in trouble.
Another scenario: You go through security and make a mental note (as above) of a potential vulnerability. You (as above) report it to the appropriate authorities. Now some time in the future you are going through airport security and you wonder to yourself "I wonder if they fixed it". So you decide to test it out. You bring a banned item through. You get caught. You are in trouble but you say in response "but I was the guy who informed you of the vulnerability and I was just checking to see if it was fixed".
Good luck with that.
My feeling is that if you notice a potential (or actual) vulnerability as part of a everyday, normal use case of a website, or a web service, or network, then fine, you can report it, and you likely won't get into trouble.
On the other hand if you additionally decide to test the system in such a way that could be misconstrued as an attack, then you will probably get into trouble.
Another analogy: you walk into Macy's and on your way in you notice that the security system they are using is outdated, and you know it is vulnerable --- (made up silly example) you know that if you break in while holding a tuna sandwich, the alarm will not go off. So that night after the store is closed and locked, you break in, while holding a tuna sandwich, and you take a pair of $300 shoes. The next day you go to the store and you say "look guys, I was able to break into your store and steal these $300 shoes." You think they will thank you? or will they call the police?