Skip to main content

Unsupported Content-Type Headers

ItemDescription
Full Fuzzer NameUnsupportedContentTypesHeadersFuzzer
Log KeyUCTH
DescriptionThis fuzzer will send different Content-Type headers from a pre-defined list. The Fuzzer will send happy path requests. The expectation is that APIs will reject requests as not supported.
Enabled by default?Yes
Target header typesAll
Expected result when fuzzed header is requiredN/A
Expected result when fuzzed header is optionalN/A
Fuzzing logicIteratively calls all paths and HTTP methods and sends Content-Type headers from a pre-defined list of headers, which are not defined in the OpenAPI specs. Expects a 415 response code.
Conditions when this fuzzer will be skippedNone
HTTP methods that will be skippedNone
ReportingReports error if: 1. response code is 404; 2. response code is documented, but not equal to 415; 3. any unexpected exception.

Reports warn if: 1. response code is expected and documented, but not matches response schema; 2. response code is expected, but not documented; 3. response code is 501.

Reports success if: 1. response code 415 .

List Of Accept Headers

"application/java-archive",
"application/javascript",
"application/octet-stream",
"application/ogg",
"application/pdf",
"application/xhtml+xml",
"application/x-shockwave-flash",
"application/ld+json",
"application/xml",
"application/zip",
"application/x-www-form-urlencoded",
"image/gif",
"image/jpeg",
"image/png",
"image/tiff",
"image/vnd.microsoft.icon",
"image/x-icon",
"image/vnd.djvu",
"image/svg+xml",
"multipart/mixed; boundary=cats",
"multipart/alternative; boundary=cats",
"multipart/related; boundary=cats",
"multipart/form-data; boundary=cats",
"text/css",
"text/csv",
"text/html",
"text/javascript",
"text/plain",
"text/xml"