CVE-2026-46358: Inverted Redaction Logic

Detected a potentially inverted redaction filter. Using '!strings.HasPrefix' with an auth-related or secret-related prefix acts as an allow-list, thus deleting all non-matching normal entries and preserving only the sensitive items that were likely meant to be redacted. Remove the negation to properly redact objects that match the prefix.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-46358-inverted-redaction-logic --engine opengrep

Description

Detected a potentially inverted redaction filter. Using '!strings.HasPrefix' with an auth-related or secret-related prefix acts as an allow-list, thus deleting all non-matching normal entries and preserving only the sensitive items that were likely meant to be redacted. Remove the negation to properly redact objects that match the prefix.