I don't know of any examples of introducing *new* deps in stable branch updates, but there have been several occasions where version requirements were bumped higher to unblock gate issues. IMHO that can be worse for stable distros (as opposed to requiring a new dependency that most can provide)
That said, I'm heavily leaning toward -1 on this as well. This isn't a new bug. Concerns about the use of the use python-oauth2 in Keystone on LP go a while now and a decision was made to ship optional oauth support in Havana's using python-oauth2. I don't think we can undo that now. A better solution would be to add a big ugly warning to documentation referencing relevant CVEs and mentioning the issue is fixed in Icehouse.
I also don't think its unreasonable for distros to carry their own cherry-picked patch from Icehouse to address the issue.