If it weren't for CVEs it would be a lot more difficult to convince management to update the codebase and get rid of legacy crap even though I'm fully aware that almost all the CVEs don't apply to our project. It's just better for productivity/QOL.
I think it's normal that CVEs don't convey all the nuance and at the end of the day, it's up to you to make an assessment on whether you're vulnerable. Though curl CVE seems like nonsense no matter how you look at it, I could see it might be an issue if delay was being set by untrusted user... but they could also set a very short delay without taking advantage of this flaw. So moot point.