“No one will ever find these vulns without source access! Fix deferred” oh wait…
Is it that (through some mechanism) an actor gained access to F5's sytems, and literally found undisclosed vulnerabilities documented within F5's source control / documentation that affects F5's products?
If so, lol.
"Here be dragons" is also a good search if you're responsible for security hardening legacy code.
Either way though, this is not a small company. DoD/Navy utilizes this all over their systems. TODO shouldn't be getting pushed to main, nor should there be security issues swept under the rug for later.
Maybe they disclosed this to some vendors previously, but I doubt.