Route uses expensive APIs without rate limiting

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

An exposed API makes use of third-party services paid for per request and does not implement any rate-limiting protection.

A malicious user could abuse this endpoint to incur significant costs, exceed your quota, and potentially disrupt your application.

Rationale

This finding works by:

  • Identifying an API that is processing traffic from the internet.
  • It was detected using a third-party paid service as a part of its operations, see the following list of services that fall in this category.
  • There is no business logic rate limiting rule associated with this endpoint

Remediation