Test Id
Test 3423
Test Trace Id
fe4b0a9f-e87d-4af9-b481-2a07cc720446
Timestamp
Tue, 23 Jun 2026 21:32:08 GMT
Scenario
Send number fields encoded as zero-prefixed number: field [bytesCount], fuzzed value [000120000], original [120000]. This tests type validation and potential type coercion issues.
Expected Result
Should return 4XX
Result
Result Details
The following keywords were detected in the response which might suggest an error details leak: [forbidden]
Contract Path
Fuzzer
LeadingZerosInNumericFields
Full Request Path
Http Method
{
"severity": "HIGH",
"destinationPort": 443,
"sourcePort": 5353,
"packetCount": 230,
"description": "Traffic burst above baseline",
"type": "UDP_FLOOD_SUSPECTED",
"deviceId": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"destinationIp": "192.168.1.10",
"bytesCount": "000120000",
"protocol": "UDP",
"sourceIp": "10.10.10.2",
"windowSeconds": 5,
"timestamp": "2026-06-01T10:00:05Z"
}
[
{
"key": "Accept",
"value": "application/json"
},
{
"key": "Content-Type",
"value": "application/json"
},
{
"key": "User-Agent",
"value": "cats/13.8.1-SNAPSHOT (Test 3423 - LeadingZerosInNumericFields)"
},
{
"key": "X-Cats-Trace-Id",
"value": "fe4b0a9f-e87d-4af9-b481-2a07cc720446"
}
]
curl -X POST \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "User-Agent: cats/13.8.1-SNAPSHOT (Test 3423 - LeadingZerosInNumericFields)" \
-H "X-Cats-Trace-Id: fe4b0a9f-e87d-4af9-b481-2a07cc720446" \
\
-d '{"severity":"HIGH","destinationPort":443,"sourcePort":5353,"packetCount":230,"description":"Traffic burst above baseline","type":"UDP_FLOOD_SUSPECTED","deviceId":"7c9e6679-7425-40de-944b-e07fc1f90ae7","destinationIp":"192.168.1.10","bytesCount":"000120000","protocol":"UDP","sourceIp":"10.10.10.2","windowSeconds":5,"timestamp":"2026-06-01T10:00:05Z"}' \
https://qa-api.puk3p.online/api/alerts
{
"responseCode": 403,
"httpMethod": "POST",
"responseTimeInMs": "127",
"numberOfWordsInResponse": "1",
"numberOfLinesInResponse": "1",
"contentLengthInBytes": "94",
"jsonBody": {
"timestamp": "2026-06-23T21:32:09.006Z",
"status": 403,
"error": "Forbidden",
"path": "/api/alerts"
},
"headers": [
{
"key": "cache-control",
"value": "no-cache, no-store, max-age=0, must-revalidate"
},
{
"key": "content-type",
"value": "application/json"
},
{
"key": "date",
"value": "Tue, 23 Jun 2026 21:32:09 GMT"
},
{
"key": "expires",
"value": "0"
},
{
"key": "pragma",
"value": "no-cache"
},
{
"key": "server",
"value": "nginx/1.24.0 (Ubuntu)"
},
{
"key": "strict-transport-security",
"value": "max-age=31536000 ; includeSubDomains"
},
{
"key": "vary",
"value": "Origin"
},
{
"key": "x-content-type-options",
"value": "nosniff"
},
{
"key": "x-frame-options",
"value": "DENY"
},
{
"key": "x-xss-protection",
"value": "0"
}
],
"responseContentType": "application/json"
}
cats replay Test3423