Tainted flow: 'req' from os.environ.get (line 93, credential/environment) → urllib.request.urlopen (network output)
Critical
- Category
- Data Flow
- Content
loop = asyncio.get_event_loop() data = await loop.run_in_executor( None, lambda: urllib.request.urlopen(req, timeout=120).read(), ) return web.Response( body=data,- Confidence
- 93% confidence
- Finding
- lambda: urllib.request.urlopen(req, timeout=120).read(),
