CVEs are always filed against a specific product. If it's in a library, then it's typically the library and not all of its user. All of that information is already in the CVE database: https://nvd.nist.gov/vuln/detail/CVE-2025-31200
What OP wanted to stress is that just the CVE number on its own is not very helpful as a title. It would be helpful to at least mention the type of vulnerability and the affected product according to the CVE database entry.