@nprofile1q... I think that when the title, or CWE of a vulnerability and a package name is publicly known it should be assumed that the actual vulnerability is easily rediscoverable.
Maybe at that point the security advisory should already be published (referencing a git commit/branch/PR even if not a full release yet). Delaying the release of the details puts defenders at a disadvantage, with only minimal impact on attackers (which can rediscover those details with other tools).