@bagder there was something similar with the h2 dB system within the last few weeks, CVE-2022-45868.
Similar thing with it not actually being an issue, the project not being informed until soneone asked them about it.