Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The default non-redirect path explicitly disables TLS certificate verification and hostname checking, which allows man-in-the-middle interception or spoofing of HTTPS endpoints. This is especially problematic because the tool presents itself as a normal HTTP inspection utility, so users are likely to assume standard HTTPS validation is still being enforced.
