All Tests  /  Test 2356

Test Id

Test 2356

Test Trace Id

155e52df-8ac8-429a-8bfc-7f7ed3606276

Timestamp

Tue, 23 Jun 2026 21:29:28 GMT

Scenario

Send a malformed JSON which has the string 'bla' at the end

Expected Result

Should return 4XX

Result

Result Details

The following keywords were detected in the response which might suggest an error details leak: [forbidden]

Contract Path

/api/account/profile

Fuzzer

MalformedJson

Full Request Path

https://qa-api.puk3p.online/api/account/profile

Http Method

put
Request Details
Payload
{
  "fullName": "Carley Boyle",
  "language": "US",
  "phone": "+1 (258) 385-8333",
  "email": "hermione.cyan@cats.io",
  "timezone": "Asia/Urumqi"
}bla
Request Details
Headers
[
  {
    "key": "Accept",
    "value": "application/json"
  },
  {
    "key": "Content-Type",
    "value": "application/json"
  },
  {
    "key": "User-Agent",
    "value": "cats/13.8.1-SNAPSHOT (Test 2356 - MalformedJson)"
  },
  {
    "key": "X-Cats-Trace-Id",
    "value": "155e52df-8ac8-429a-8bfc-7f7ed3606276"
  }
]
Request Details
cURL
curl  -X PUT \
     -H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "User-Agent: cats/13.8.1-SNAPSHOT (Test 2356 - MalformedJson)" \
-H "X-Cats-Trace-Id: 155e52df-8ac8-429a-8bfc-7f7ed3606276" \
 \
      -d '{"fullName":"Carley Boyle","language":"US","phone":"+1 (258) 385-8333","email":"hermione.cyan@cats.io","timezone":"Asia/Urumqi"}bla' \
      https://qa-api.puk3p.online/api/account/profile
Response
{
  "responseCode": 403,
  "httpMethod": "PUT",
  "responseTimeInMs": "138",
  "numberOfWordsInResponse": "1",
  "numberOfLinesInResponse": "1",
  "contentLengthInBytes": "103",
  "jsonBody": {
    "timestamp": "2026-06-23T21:29:28.943Z",
    "status": 403,
    "error": "Forbidden",
    "path": "/api/account/profile"
  },
  "headers": [
    {
      "key": "cache-control",
      "value": "no-cache, no-store, max-age=0, must-revalidate"
    },
    {
      "key": "content-type",
      "value": "application/json"
    },
    {
      "key": "date",
      "value": "Tue, 23 Jun 2026 21:29:28 GMT"
    },
    {
      "key": "expires",
      "value": "0"
    },
    {
      "key": "pragma",
      "value": "no-cache"
    },
    {
      "key": "server",
      "value": "nginx/1.24.0 (Ubuntu)"
    },
    {
      "key": "strict-transport-security",
      "value": "max-age=31536000 ; includeSubDomains"
    },
    {
      "key": "vary",
      "value": "Origin"
    },
    {
      "key": "x-content-type-options",
      "value": "nosniff"
    },
    {
      "key": "x-frame-options",
      "value": "DENY"
    },
    {
      "key": "x-xss-protection",
      "value": "0"
    }
  ],
  "responseContentType": "application/json"
}
CATS Replay
cats replay Test2356