Those CVEs seem a little more subtle than OID serialization issues. In the first example there are actually two distinct problems in concert that lead to the vulnerability, one of which is when a "low public exponent" is used.
https://github.com/digitalbazaar/forge/commit/3f0b49a0573ef1...