Earlier quoted context omitted.
It took 8 years for somebody to discover this. It can't have been that obvious.
Not everyone cares about Cloudflare, or even HTTP/2. The exploit has more to do with their implementation than the protocol.
Is it? I imagine that implementations can do things like make creating/dropping a stream faster but how would an implementation flat out mitigate this?