I wouldn't say that multiple implementations are duplicating the attack surface since most users will not end up running them in parallel.
If anything this is a even a good thing, since it means that each individual vulnerability an attacker finds is less valuable to them.