 
            How important is this bug ? eg security ?
It's a local filesystem racecondition, which may cause an overflow on the heap. It's likely to be hard to trigger the race, and creating successful exploit code that doesn't just crash the server is probably very hard, since it's a heap overflow.
Because if this can allow remote access to webservers like Roxen, Chilimoon or Caudium we should be prepared to work fast.
By the way, is this bug can push a new pike 7.6 version ?
Yes.