Hey Mozilla, the CVE program made a statement that smells almost directed at you:
"The CVE Program does not support assigning a single CVE ID to multiple distinct vulnerabilities when those vulnerabilities are independently understandable, independently exploitable, independently fixable, or independently relevant to defenders"
https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification