An alert fires: one route at a 100% error rate, dozens of failures, every log line identical. The traffic is a single host running an automated client, probing for /.env and /.DS_Store. No real visitor is affected. The route is fine for everybody else.
How the probe gets in
A localisation proxy has to skip any path containing a dot, or every font and image in your public folder gets handed a language prefix. That exclusion also means dotted paths never reach language negotiation at all. They fall straight through into the dynamic language segment, which happily matches a single path segment, and the application is asked to render a page in a language called .env.
The metadata function usually runs before the layout's validity guard, so the invalid value reaches the translation loader first and the render fails there. The log then reports a missing 500 page, which is a symptom rather than the cause.
Fix the cause, not the symptom
Adding the missing error page would hide the failure and keep the 500 status. The fix is to refuse unknown languages before any of that code runs, so a probe gets a clean 404 and the route never enters an error state.
Nothing flags this. The build is green, every real page works, and it takes a scanner to find it. Which is why it shipped twice.


