Tainted flow: 'headers' from os.getenv (line 74, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
# 3. 发起请求 if method.upper() == "GET": response = requests.get( api_endpoint, headers=headers, params=api_params,- Confidence
- 99% confidence
- Finding
- response = requests.get( api_endpoint, headers=headers, params=api_params, timeout=30 )
