Hmmm, this seems like a bug to me. Anything enclosed within CODE tags should be safe, so there should be no need to filter it.