The post links to more context here: https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-eve...
Last year, someone got got CVE's assigned for a curl issue for code that didn't exist AND managed to get a high severity assigned to it. So curl becoming a CNA lets them provide some control to this process.