Resource Limitation: Response Size Exceeded¶
Identifier:
response_size
Scanner Support¶
| GraphQL Scanner | REST Scanner | WebApp Scanner | ASM Scanner | Automated Pentest |
|---|---|---|---|---|
Description¶
Applications sending back much larger responses than intended can strain servers and clients, potentially leading to denial of service attacks where attackers intentionally trigger oversized responses to overwhelm resources.
How we test: We monitor response sizes from API endpoints and analyze if responses exceed configured limits. We check if applications properly validate input and enforce response size limits to prevent resource exhaustion attacks.
Configuration¶
Example¶
Example configuration:
Reference¶
max_length¶
Type: integer
The maximum length of the response in bytes.
skip¶
Type: boolean
Skip the test if true.