If you do examine what it’s doing you will catch this as soon as an attacker exploits it, and can disable it. Also, you should maybe not run the entire production with experimental features enabled. In a stable feature this would absolutely be a CVE, but this is marked experimental because it might not work right or even crash, like here
That means if you’re large enough that A can pick up the slack if B shits the bed. The only impact would be that you have to use HTTP2