That's a pretty strong statement considering there was an extended review period before merging and no one expressed any concerns.
Instead of singling out a single person, I think it's more accurate to say the security community in general dropped the ball by not bringing concerns earlier to the maintainer who performed the merge(s).