As far as I can tell the existing policy is not to allow public repos of a zero day vuln exploit while it is still unpatched. The code is allowed after the issue is mitigated
This seems like a pretty reasonable policy all things considered
Put the zip file to your static site, mirror to bitbucket, mirror to sourcehut. I have more doubts, that you don't find the code. Maybe a link inside the CVE would be good.