Last year Vercel bungled the security response to a vulnerability in Next's middleware. This is nothing new.
https://news.ycombinator.com/item?id=43448723
https://xcancel.com/javasquip/status/1903480443158298994