Open
Description
Description of the false positive
Either this is a false positive on function post_to_clbin
, or the post_to_0x0
function below is being missed by the analysis despite containing nearly identical code.
I'm not really sure what we're doing in that code actually has anything to do with URL substring sanitization, but what actually bugs me is the reporting inconsistency.
URL to the alert on the project page on LGTM.com