If you're suggesting a private disclosure channel, made for all the maintainers of the ~600 actively maintained distributions (including those that pop into existence just to get access to the disclosures), then that would be a point you could make. But, that text above is reasonable, because the mailing lists they're referring to are public.
Open source code process must assume bad actors are involved (because they have been historically, and will be always and forever). So, this isn't some "easy" scenario. Talking to the guy that can fix it first, and assumed the distributions contain bad actors, then disclosing to them once the fix is available, is reasonable, and I don't see an alternative.
I would be interested in seeing what the thoughts are on a proper disclosure cycle, for those 600 distributions. Seems very complex.