> but the commit was not documented as a security fix and received no CVE.
There must be an entire class of open source commits that unknowingly fixed security bugs without being tagged as security fixes that one could look for missed backports. Scary.