Vulnerabilities and scanning

Taint tracking

Taint tracking, also called taint analysis, follows data from input sources (HTTP parameters, file reads, message bodies) through a program to sensitive sinks (database queries, shell commands, DOM insertion). A finding fires when tainted data reaches a sink without passing through a recognized sanitizer. Because it follows the data path rather than matching text, it can tell a dangerous call that receives user input from one that does not. Deva's scanner includes taint-mode rules across its supported languages.