This is the part I don’t understand:
For each finding, we provided a detailed vulnerability description, root cause analysis, and a proof of concept generated directly by our system.
They submitted 5 findings. Only 4 of them were confirmed by Nginx.
If the findings had everything, including a proof of concept, why was one of them not accepted?
Did they manually test these proof of concepts?
I’m guessing they found something that is not actually exploitable from outside the software, but they were too excited to consider that and submitted it anyway. They made the Nginx team do the work of verifying it properly.