That is exactly why many big projects are migrating to becoming CNA, so that randos can’t get assigned unqualified CVEs which nobody has looked at or validated.

Apparently RedHat is a CNA of last resort, so it might be possible to get your project under Redhat’s scope and go through them without having to be a CNA yourself.

What are the requirements to become a CNA?

The OSSF (Open Source Security Foundation) has a nice guide on how to become a CNA [0]. It's pretty involved though.

[0] https://github.com/ossf/wg-vulnerability-disclosures/blob/ma...