Skip to main content

Extreme Negative Numbers In Integers

ItemDescription
Full Fuzzer NameExtremeNegativeNumbersInIntegerFieldsFuzzer
Log KeyENNIIF
DescriptionThis fuzzer will send outside the range values in integer fields. The expectation is that APIs will reject the request as invalid as they might potentially break downstream systems. Furthermore, APIs should update their specs to define clear boundaries (minimum, maximum) for these fields.
Enabled by default?Yes
Target field typesOpenAPI type integer
Expected result when fuzzed field is required4XX
Expected result when fuzzed field is optional4XX
Expected result when fuzzed value is not matching field pattern4XX
Fuzzing logicIteratively replaces integer fields with extreme negative integer values: -9223372036854775808 for format int32 and -18446744073709551616 for format int64
Conditions when this fuzzer will be skippedWhen field is not of type integer
HTTP methods that will be skippedNone
ReportingReports error if: 1. response code is 404; 2. response code is documented, but not expected; 3. any unexpected exception.

Reports warn if: 1. response code is expected and documented, but not matches response schema; 2. response code is expected, but not documented; 3. response code is 501.

Reports success if: 1. response code is expected, documented and matches response schema.