It often makes up non existent vulnerabilities. I think it was curl getting flooded with fake vulnerability reports which drowns out real reports, esp because it can take time to parse through the code or run the poc
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments