If you do examine what it's doing you will catch this as soon as an attacker exploits it, and can disable it. Also, you should maybe not run the entire production with experimental features enabled. In a stable feature this would absolutely be a CVE, but this is marked experimental because it might not work right or even crash, like here
It was on purpose on the side of the road so people could gice feedback. But the issue wasn't a health issue (privilege escalation, etc), it just wasn't tasty (DoS). Something you really don't want to sell in the store, but in an alpha/beta version it's no big deal
It's an experimental feature. It doesn't need a bugfix release because you're not supposed to run it in production, and it's just a DoS, not privilege escalation or something
You just have to make it think it wasn't you