
A regex check looks correct. The decoder runs afterward. The SAST tool sees clean dataflow and moves on. This is why OpenAIs new vulnerability detection agent excludes SAST reports from its starting point, and why that design choice matters. The CVE-2024-29041 vulnerability in Express.js (a popular Node.js web framework) allowed attackers to bypass URL allowlists by encoding newlines as %0d%0a, which the regex check saw as benign but the decoder turned into actual newline characters for HTTP header injection. The actual exploit worked like this: an attacker submits https://evil.com%0d%0aLocation:%20https://target.com, the allowlist sees a safe URL, the decoder converts the %0d%0a into real newlines, and the redirect becomes a header injection. This is the most substantive technical explanation of the SAST limitation that a major AI lab has published, appearing in OpenAI's March 6, 2026 blog post announcing Codex Security. https://type0.ai/articles/why-openai-built-codex-security-to-ignore-sast-reports
Post summary
The post explains how CVE‑2024‑29041 in Express.js allows attackers to bypass URL allowlists via newline encoding, enabling header injection, but provides no PoC, active exploitation evidence, or patch information.
