I submitted a very detailed bug report[0] a while ago, which can lead to a DoS (albeit in a very specific setting). I don't expect anyone to rush to fix it, but I'm surprised that there isn't even a comment about it. Is there another place it needs to be reported in?
Try pointing it out on the mailing list ( openssh-unix-dev@mindrot.org ).
Having been on both user and the developer sides, with F/OSS projects, more developers are likely to read every post on the mailing list than every report in the bug tracker.
[0] https://bugzilla.mindrot.org/show_bug.cgi?id=2265