Post #1590305
2026-04-12 14:14 UTC
@yossarian Not at all! It's a fairly common one for CPython.
Replies (2)
-
@ancoghlan@mastodon.social 2026-04-12 14:34
@hugovk @yossarian It's kind of a variant on "No vulnerability outside of usage", since "We used an API with an explicit security disclaimer in a security sensitive context" *is* a vulnerability, but the mere existence of APIs that are designed solely for trusted input is *not* a vulnerability. Not quite the same situation as the examples given, but similar.
-
@yossarian@infosec.exchange 2026-04-12 16:10
@hugovk added it here! https://blog.yossarian.net/2026/04/11/Brocards-for-vulnerability-triage#no-vuln-from-documented-behavior