Tainted flow: 'headers' from os.getenv (line 349, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
debug_print(f"result is {url}") debug_print(f"headers is {headers}") debug_print(f"url is {url}, body is {body_bytes}") resp = requests.post(url, data=body_bytes, headers=headers, timeout=30) try: result = resp.json()- Confidence
- 79% confidence
- Finding
- resp = requests.post(url, data=body_bytes, headers=headers, timeout=30)
