Dear Ronak,
I am terribly sorry but we are a Free Software project with very little funding so there is no bug bounty and the closest we have got to a hall of fame is our contributors page (
http://www.gnustep.org/developers/whoiswho.html). Vulnerabilities should just like any other bugs be reported on our Savannah page (
http://savannah.gnu.org/projects/gnustep/) or if you prefer on
https://github.com/gnustep. Or if all of this is too much hassle for you, just write a mail to this list or to me in person.
Hope this helps,
Fred
PS: I looked at your LinkedIn page and your record so far is impressive.