[flagged]
They should have included a patch though and they should have contacted ffmpeg team first before spamming them with dozens of issues all at once.
I don't know how a vulnerability report could be much better than that. It is a real vulnerability. The report includes a detailed analysis of where the vulnerability is. The bug has been validated, and the report includes exact reproduction instructions.
How is that a bullshit bug report?
The human idiot "researchers" will send paragraph long automatically generated extortion threats over not sending HSTS header