Tainted flow: 'headers' from os.getenv (line 119, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
} try: response = requests.post( BIND_URL, headers=headers, data=json.dumps(payload, ensure_ascii=False).encode("utf-8"),- Confidence
- 95% confidence
- Finding
- response = requests.post( BIND_URL, headers=headers, data=json.dumps(payload, ensure_ascii=False).encode("utf-8"), timeout=30, )
