False positives

Last updated: Oct 1, 2026


Definition

A false positive is an incorrect alert that says that there is a vulnerability. False positives are an important problem in software development projects. It can be slower to examine them than to examine correct alerts. Also, the morale of developers can decrease when these alerts change their priorities.

Report false positives

The Fluid Attacks solution has very low false positive rates. For example, it got a false positive rate of 0% in the OWASP Benchmark Project. But your organization can find that a report is a false positive, or that a vulnerability is not a risk. Then, from the platform, you can send Fluid Attacks a request to examine the report. This function is the False positive request (learn how to use it).

The sections below tell when Fluid Attacks accepts or rejects a false positive request.

Reasons to accept false positive requests

  • Overlooked context: When Fluid Attacks examined the vulnerability context, it found an inherent mitigation that the previous analysis missed.
  • CVE expiration: The Common Vulnerabilities and Exposures (CVE) entry of the reported vulnerability expired.
  • Misreport: The report is incorrect, or the vulnerability is not a risk.
  • Report duplication: The report is a duplicate.

Reasons to reject false positive requests

  • Obfuscation by countermeasure: The vulnerability is there, but a countermeasure, for example a WAF, obfuscates or mitigates it.
  • Reference to remediation: Fluid Attacks does not dismiss a vulnerability because no remediation is available, or because the remediation is too complex.
  • Reference to exploitability: Fluid Attacks does not dismiss a vulnerability because it is hard or not possible to exploit.
  • Reference to scope: A report can be out of the intended scope of the tests, because it belongs in a different group. That does not make it a false positive, and it does not remove its risk.
  • Incorrect procedure: Someone sent a false positive request, but the correct procedure was to request a reattack.
  • Inactivity: The discussion with the client about the report stops, because the client does not give more details. Then Fluid Attacks rejects the false positive request.

On this page