LB: the vuln itself is crazy, but even crazier is the way Vercel decided to handle the whole thing
Post by researchers: https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware
Summary of Vercel situation: https://xcancel.com/amasad/status/1903654014962819448