Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
{ "binaries": [ { "binary_version": "8.5.8+dfsg-5", "binary_name": "gitlab" } ] }