Well, they clearly don't if they have an "insecure argument handling" vulnerability.
As others here have said already here, its an "venerable and ancient class of bugs".
Its the sort of thing that should be picked up by modern defensive programming that includes fuzz testing.
And it is CERTAINLY the sort of thing that should be flagged by any competent security audit. "insecure argument handling" is bread-and-butter for security auditors.
> I can't take this seriously. If you were a customer you could, you know, ask them? Or inspect their SOC2 documents?
SOC2, ISO27001 and all that shit is not the same thing.
As I said, anyone serious who is proud of having had their software audited as clean would publish their reports in public. Nothing to hide. And it strengthens your case with customers.
It can always be a suitably redacted management summary written by the auditor. That's what everyone else does.