It is our moral imperative to consider the "real world" and actual users when assessing the possible security impact of a reported #curl issue. If we deem that there is likely to be zero affected users, then we do more damage than good by insisting on doing the security dance for the issue.
Then we end up with a severity level that is below LOW, and then we treat it as a bug instead. For the good of mankind.