Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.