if the tool isn't ran it can't be exploited
CVE should just be far more granular instead of flagging alert for anything using zlib