WAF protection coverage

Measured 2026-09-17 by the coverage library on Clearplane 1.0.0-alpha4. CRS source: OWASP CRS v4.29.0 (commit ab3ccd5fcd691424ba3f320d4040c61417270193).

The report measures request replays and any explicitly configured response or API-schema traffic cases. It does not establish coverage for streamed WebSocket or gRPC messages, live application behavior, or browser challenges. It measures only the listed ruleset inputs; it does not establish which Cloud releases are available or which releases a gateway runs.

Application exclusion policy

The following route opt-ins apply to every attack and benign case from the named source. Other traffic sources and the generic CRS regression suite use the default policy. Source classifications, request bytes and denominators are preserved.

Vendored source Opted-in exclusion rulesets
crs-plugin-nextcloud clearplane-exclusions-nextcloud-core
crs-plugin-phpmyadmin clearplane-exclusions-phpmyadmin-core
crs-plugin-wordpress clearplane-exclusions-wordpress-core

The following route settings allow additional methods or request content types for every case from the named source, the way an operator configures the route that serves that application or harness.

Vendored source Additional allowed methods Additional request content types
crs-responses — text/plain, text/html

Adapted CRS expectations

The following approved corrections for platform behavior and Clearplane default policy apply only to pinned requests and their original expectations. The cases are replayed and must satisfy the Clearplane expectation; they are not skipped. Numerical targets, request bytes and independent traffic classifications remain unchanged. Expected-ID and no-expect subtotals reflect the effective expectations. Original expectations and observed source-rule IDs remain recorded below and in the JSON report.

Test Request SHA-256 Original expected IDs Original prohibited IDs Clearplane expected IDs Clearplane prohibited IDs Observed IDs Reason
911100-6 56900fb52bc723a3d69e8eb4b9983e378f1d0d71aa071317939f74cacecdffad 911100 911100 Clearplane's default method policy allows PUT, PATCH and DELETE in addition to the CRS defaults, as approved on 2026-09-16 for REST applications. This exact DELETE request must not match rule 911100; methods outside the default list still do. Request bytes and numerical targets are unchanged.
920620-1 aa6a485905c86602489c4fda4af8b156699c5906e979accc6d42cb633261efe8 920620 920620 920620 The pinned CRS fixture expects Apache httpd to combine two Content-Type headers. Clearplane preserves both headers and must detect the duplicate with rule 920620. Only this exact request and original expectation are adapted; request bytes, detection policy and numerical targets are unchanged.
953101-1 18bcab03e79330a236fbce3e4ee95ed5f171a489f74c3bf9291ceeb136c846de 953101 953101 The pinned CRS fixture expects ordinary validation prose to match PHP data-leakage rule 953101. The same text is a benign response control. Clearplane reports a PHP leak only with PHP diagnostic context, as approved on 2026-09-16, so this exact response must not match. Response bytes and numerical targets are unchanged.
953101-2 bce85898c40e3fcaf63e0dec397c028f97a0316c078c8eef78d93628c74aebe6 953101 953101 The pinned CRS fixture expects ordinary validation prose to match PHP data-leakage rule 953101. The same text is a benign response control. Clearplane reports a PHP leak only with PHP diagnostic context, as approved on 2026-09-16, so this exact response must not match. Response bytes and numerical targets are unchanged.
953101-3 74325df4202cb996c9555d5fe9ba68618743f244594cbf774c1162eb752b9ee9 953101 953101 The pinned CRS fixture expects ordinary validation prose to match PHP data-leakage rule 953101. The same text is a benign response control. Clearplane reports a PHP leak only with PHP diagnostic context, as approved on 2026-09-16, so this exact response must not match. Response bytes and numerical targets are unchanged.
953101-4 32dc0ed5b14f7a18167274c3fe673cebe21ada024935adc1a8dd2f75fa25b91a 953101 953101 The pinned CRS fixture expects ordinary validation prose to match PHP data-leakage rule 953101. The same text is a benign response control. Clearplane reports a PHP leak only with PHP diagnostic context, as approved on 2026-09-16, so this exact response must not match. Response bytes and numerical targets are unchanged.
953101-5 e693093d7808c40448ab453f6f598efc43ff896a7655e0502130b230fd3f40f8 953101 953101 The pinned CRS fixture expects ordinary validation prose to match PHP data-leakage rule 953101. The same text is a benign response control. Clearplane reports a PHP leak only with PHP diagnostic context, as approved on 2026-09-16, so this exact response must not match. Response bytes and numerical targets are unchanged.

Rulesets

Ruleset Version Payload SHA-256
clearplane-api-schema 1.0.0 a75b066588c7bcc5c38f89857edf738f5cfbbbe3c48cff28b42fee0350b39ace
clearplane-command-injection 0.0.0 93d8a51abfbedc87c0d028651b75f9415bcc75b277e0783f45ea4c379af4e0e2
clearplane-data-leakage 0.0.0 a0f94b9b65c884d1590a95979531f3ae7da86764cd644b06688d62d390821d80
clearplane-exclusions-nextcloud-core 1.0.0 229e667485a7d617cbdb3cad808b6137d20dbcc883e68a77d7b53163f8288d3d
clearplane-exclusions-phpmyadmin-core 1.0.0 3fe608ec0bb2f2765360613e63ab71cf7807ea3e98d47c909a34c6fc55099c58
clearplane-exclusions-wordpress-core 1.0.0 259cf38678b35cbbd5889b96ec5487d070e1b37ebc98c1a93dc99a18f5a5e799
clearplane-path-traversal 0.0.0 23a8e38cd274eec4d7d71e635628e418304e2ea7f19ec5fcb58125a4ec1dbb27
clearplane-protocol 0.0.0 9d7901ad8eb68e530aeed29c636443e3fbcbd16b789a527fd0703c4502ff72d6
clearplane-scanners 0.0.0 a2f84dad83bde304c35d7397c3eeae8c14eedf1832c13e12324904974330ce5c
clearplane-sql-injection 0.0.0 835ee29f5bbf676e4eb8df8742499b40aa58c440a21a5e54aab1625e8e954f17
clearplane-xss 0.0.0 a61274f2a0285a78848090be478f9d084188d5973a95c5057eeef4f8966a3ede

Categories

Targets apply to CRS source levels 1–2 and attack runs at levels 1–2. Levels 3–4 are reported without targets. “Met” requires measured CRS category or attack coverage, measured benign results at both levels 1 and 2, complete evaluation of that category's CRS/attack cases and every benign case at both targeted levels, and no failed target. CRS tests containing only prohibited-ID expectations are benign for this completeness check. Incomplete evidence is “Not measured” unless a measured target failed, which is “Not met”. Unmeasured targets remain unmeasured. Counts and percentages below are taken from the report.

Category Status CRS category PL1–2 CRS strict PL1–2 CRS no-expect PL1–2 Attack traffic PL2 Benign PL1 Benign PL2
api-schema Met not measured not measured not measured 100.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
command-injection Met 96.32 % (≥ 95.00 %) 93.44 % (≥ 90.00 %) 0 (≤ 0) 95.65 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
data-leakage Met 100.00 % (≥ 95.00 %) 100.00 % (≥ 90.00 %) 0 (≤ 0) 100.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
deserialization Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
file-upload Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
generic-injection Not met 0.00 % (≥ 95.00 %) 0.00 % (≥ 90.00 %) 0 (≤ 0) not measured 0 (≤ 0) 0.00 % (≤ 0.10 %)
graphql Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
java-injection Not met 0.00 % (≥ 95.00 %) 0.00 % (≥ 90.00 %) 0 (≤ 0) not measured 0 (≤ 0) 0.00 % (≤ 0.10 %)
jwt Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
ldap-injection Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
nosql-injection Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
open-redirect Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
path-traversal Met 100.00 % (≥ 95.00 %) 100.00 % (≥ 90.00 %) 0 (≤ 0) 100.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
php-injection Not met 0.00 % (≥ 95.00 %) 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
protocol Met 95.56 % (≥ 95.00 %) 94.81 % (≥ 90.00 %) 0 (≤ 0) 100.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
prototype-pollution Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
remote-file-inclusion Not met 0.00 % (≥ 95.00 %) 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
scanner Met 100.00 % (≥ 95.00 %) 100.00 % (≥ 90.00 %) 0 (≤ 0) 100.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
session-fixation Not met 0.00 % (≥ 95.00 %) 0.00 % (≥ 90.00 %) 0 (≤ 0) not measured 0 (≤ 0) 0.00 % (≤ 0.10 %)
sql-injection Met 98.53 % (≥ 95.00 %) 96.09 % (≥ 90.00 %) 0 (≤ 0) 100.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
ssrf Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
ssti Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
xpath-injection Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
xss Met 98.55 % (≥ 95.00 %) 98.55 % (≥ 90.00 %) 0 (≤ 0) 100.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)
xxe Not met not measured not measured not measured 0.00 % (≥ 90.00 %) 0 (≤ 0) 0.00 % (≤ 0.10 %)

CRS rows group and replay tests at the original CRS rule's paranoia level. Strict and category rates both divide by expected-ID tests, including unsupported expected IDs. Skipped tests are excluded. The platform-specific corrections above replace only their named expectations. Strict passes require the expected source rule IDs; category passes require a match in the expected category. No-expect false positives count tests that fired a prohibited source rule ID. Strict rates compare source rule identities, not just attack detection; a zero strict rate does not imply a zero category detection rate.

Attack detection requires a match in the expected category. Category benign false positives require that category's request score to reach 5 or its response score to reach 4. Case totals count request cases, including placements of the same payload. Benign PL1 and CRS no-expect targets are counts; the other targets are rates. A dash means no denominator was measured.

api-schema

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 259 259 100.00 % 872 0 0.00 %
2 259 259 100.00 % 872 0 0.00 %
3 259 259 100.00 % 872 0 0.00 %
4 259 259 100.00 % 872 0 0.00 %

command-injection

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 548 387 369 95.35 % 376 97.16 % 5 13 161 0
2 335 238 215 90.34 % 226 94.96 % 6 17 97 0
3 121 82 81 98.78 % 82 100.00 % 1 0 39 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 182 14 7.69 % 872 0 0.00 %
2 184 176 95.65 % 872 0 0.00 %
3 184 176 95.65 % 872 59 6.77 %
4 184 176 95.65 % 872 59 6.77 %

data-leakage

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 72 66 66 100.00 % 66 100.00 % 0 0 6 0
2 11 5 5 100.00 % 5 100.00 % 0 0 6 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 71 66 92.96 % 872 0 0.00 %
2 71 71 100.00 % 872 0 0.00 %
3 71 71 100.00 % 872 0 0.00 %
4 71 71 100.00 % 872 0 0.00 %

deserialization

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 26 0 0.00 % 872 0 0.00 %
2 26 0 0.00 % 872 0 0.00 %
3 26 0 0.00 % 872 0 0.00 %
4 26 0 0.00 % 872 0 0.00 %

file-upload

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 29 0 0.00 % 872 0 0.00 %
2 29 0 0.00 % 872 0 0.00 %
3 29 0 0.00 % 872 0 0.00 %
4 29 0 0.00 % 872 0 0.00 %

generic-injection

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 132 117 0 0.00 % 0 0.00 % 0 117 15 0
2 126 107 0 0.00 % 0 0.00 % 0 107 19 0
3 13 9 0 0.00 % 0 0.00 % 0 9 4 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 0 0 — 872 0 0.00 %
2 0 0 — 872 0 0.00 %
3 0 0 — 872 0 0.00 %
4 0 0 — 872 0 0.00 %

graphql

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 5 0 0.00 % 872 0 0.00 %
2 5 0 0.00 % 872 0 0.00 %
3 5 0 0.00 % 872 0 0.00 %
4 5 0 0.00 % 872 0 0.00 %

java-injection

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 628 601 0 0.00 % 0 0.00 % 0 601 27 0
2 189 183 0 0.00 % 0 0.00 % 0 183 6 0
3 330 330 0 0.00 % 0 0.00 % 0 330 0 0
4 26 26 0 0.00 % 0 0.00 % 0 26 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 0 0 — 872 0 0.00 %
2 0 0 — 872 0 0.00 %
3 0 0 — 872 0 0.00 %
4 0 0 — 872 0 0.00 %

jwt

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 2 0 0.00 % 872 0 0.00 %
2 2 0 0.00 % 872 0 0.00 %
3 2 0 0.00 % 872 0 0.00 %
4 2 0 0.00 % 872 0 0.00 %

ldap-injection

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 152 0 0.00 % 872 0 0.00 %
2 152 0 0.00 % 872 0 0.00 %
3 152 0 0.00 % 872 0 0.00 %
4 152 0 0.00 % 872 0 0.00 %

nosql-injection

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 93 0 0.00 % 872 0 0.00 %
2 93 0 0.00 % 872 0 0.00 %
3 93 0 0.00 % 872 0 0.00 %
4 93 0 0.00 % 872 0 0.00 %

open-redirect

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 271 0 0.00 % 970 0 0.00 %
2 271 0 0.00 % 970 0 0.00 %
3 271 0 0.00 % 970 0 0.00 %
4 271 0 0.00 % 970 0 0.00 %

path-traversal

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 72 57 57 100.00 % 57 100.00 % 0 0 15 0
2 11 10 10 100.00 % 10 100.00 % 0 0 1 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 272 238 87.50 % 872 0 0.00 %
2 272 272 100.00 % 872 0 0.00 %
3 272 272 100.00 % 872 0 0.00 %
4 272 272 100.00 % 872 0 0.00 %

php-injection

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 349 261 0 0.00 % 0 0.00 % 0 261 88 0
2 27 12 0 0.00 % 0 0.00 % 0 12 15 0
3 49 39 0 0.00 % 0 0.00 % 0 39 10 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 9 0 0.00 % 872 0 0.00 %
2 9 0 0.00 % 872 0 0.00 %
3 9 0 0.00 % 872 0 0.00 %
4 9 0 0.00 % 872 0 0.00 %

protocol

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 388 218 205 94.04 % 207 94.95 % 2 11 170 0
2 90 52 51 98.08 % 51 98.08 % 0 1 38 0
3 32 15 13 86.67 % 13 86.67 % 0 2 17 0
4 23 11 11 100.00 % 11 100.00 % 0 0 12 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 44 10 22.73 % 872 0 0.00 %
2 45 45 100.00 % 872 0 0.00 %
3 47 47 100.00 % 872 97 11.12 %
4 48 48 100.00 % 872 372 42.66 %

prototype-pollution

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 13 0 0.00 % 872 0 0.00 %
2 13 0 0.00 % 872 0 0.00 %
3 13 0 0.00 % 872 0 0.00 %
4 13 0 0.00 % 872 0 0.00 %

remote-file-inclusion

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 16 14 0 0.00 % 0 0.00 % 0 14 2 0
2 25 22 0 0.00 % 0 0.00 % 0 22 3 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 0 0 — 872 0 0.00 %
2 1 0 0.00 % 872 0 0.00 %
3 1 0 0.00 % 872 0 0.00 %
4 1 0 0.00 % 872 0 0.00 %

scanner

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 7 5 5 100.00 % 5 100.00 % 0 0 2 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 8 8 100.00 % 872 0 0.00 %
2 8 8 100.00 % 872 0 0.00 %
3 8 8 100.00 % 872 0 0.00 %
4 8 8 100.00 % 872 0 0.00 %

session-fixation

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 47 42 0 0.00 % 0 0.00 % 0 42 5 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 0 0 — 872 0 0.00 %
2 0 0 — 872 0 0.00 %
3 0 0 — 872 0 0.00 %
4 0 0 — 872 0 0.00 %

sql-injection

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 373 322 320 99.38 % 320 99.38 % 2 0 51 0
2 588 497 467 93.96 % 487 97.99 % 4 26 91 0
3 50 39 38 97.44 % 39 100.00 % 1 0 11 0
4 14 8 6 75.00 % 6 75.00 % 2 0 6 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 4 4 100.00 % 872 0 0.00 %
2 4 4 100.00 % 872 0 0.00 %
3 5 5 100.00 % 872 15 1.72 %
4 5 5 100.00 % 872 37 4.24 %

ssrf

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 53 0 0.00 % 872 0 0.00 %
2 53 0 0.00 % 872 0 0.00 %
3 53 0 0.00 % 872 0 0.00 %
4 53 0 0.00 % 872 0 0.00 %

ssti

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 214 0 0.00 % 872 0 0.00 %
2 214 0 0.00 % 872 0 0.00 %
3 214 0 0.00 % 872 0 0.00 %
4 214 0 0.00 % 872 0 0.00 %

xpath-injection

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 10 0 0.00 % 872 0 0.00 %
2 10 0 0.00 % 872 0 0.00 %
3 10 0 0.00 % 872 0 0.00 %
4 10 0 0.00 % 872 0 0.00 %

xss

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 240 186 183 98.39 % 183 98.39 % 3 0 54 0
2 21 21 21 100.00 % 21 100.00 % 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 149 120 80.54 % 872 0 0.00 %
2 149 149 100.00 % 872 0 0.00 %
3 149 149 100.00 % 872 0 0.00 %
4 149 149 100.00 % 872 0 0.00 %

xxe

CRS source PL Tests Expected-ID tests Strict passed Strict rate Category passed Category rate Failed Unsupported No-expect tests False positives
1 0 0 0 — 0 — 0 0 0 0
2 0 0 0 — 0 — 0 0 0 0
3 0 0 0 — 0 — 0 0 0 0
4 0 0 0 — 0 — 0 0 0 0
Run PL Attack cases Detected Detection rate Benign cases False positives False-positive rate
1 59 0 0.00 % 872 0 0.00 %
2 59 0 0.00 % 872 0 0.00 %
3 59 0 0.00 % 872 0 0.00 %
4 59 0 0.00 % 872 0 0.00 %

Combined benign results

These results count benign cases whose combined request score reaches 5 or combined response score reaches 4 across all loaded rulesets. Request and response scores are evaluated separately. They differ from the per-category benign results above and are not summed across paranoia levels.

Paranoia level Benign cases Threshold reached False-positive rate
1 970 0 0.00 %
2 970 0 0.00 %
3 970 144 14.85 %
4 970 388 40.00 %

Application content

Application content is attack-shaped input that specific applications accept, such as source code, markup, SQL statements, serialized data or control characters. It is neither an attack nor a benign control. The default rulesets are expected to block it; applications that accept it opt out with an exclusion ruleset or by disabling rulesets for their routes.

Paranoia level Cases Threshold reached Block rate
1 23 9 39.13 %
2 23 20 86.96 %
3 23 23 100.00 %
4 23 23 100.00 %

Vendored input classifications

Classification uses the source payload and its request context before evaluating rules. Benign reclassifications remain in the benign regression traffic. A benign scope limits a case to the listed categories: it is a false positive only when those categories reach the threshold, because other categories may correctly flag the same attack-list payload. Placement corrections keep their attack classification. The JSON report records each case, source path and line, original payload SHA-256, original and effective categories and roles, benign scope, and reason.

Source Original category Effective category Original role Effective role Benign scope Request cases Reason
crs-plugin-drupal — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 942430 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 84 The pinned FTW stage prohibits CRS detection rule IDs 911100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920272, 920273, 920420, 921110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 3 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920272, 920273, 920420, 921110, 932240, 942200, 942340, 942370, 942430, 942431, 942432, 942490 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 4 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920272, 920273, 932236, 942430, 942431, 942432, 942440 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920272, 920273, 941100, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 5 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920273, 930120, 932240, 941110, 942200, 942370, 942340, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920273, 932350, 941100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920273, 941100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920273, 941110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920273, 942100, 942200, 942370, 942431, 942432, 942460, 942520 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 4 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920420, 920272, 920273, 920530, 921110, 942430, 942431, 942432, 942440 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920420, 941160 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 8 The pinned FTW stage prohibits CRS detection rule IDs 911100, 920440 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 911100, 921110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 3 The pinned FTW stage prohibits CRS detection rule IDs 911100, 932200, 933210, 941110, 942200, 942260, 942370, 942430, 942440 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 911100, 932236 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 911100, 932236, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 911100, 941100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 911100, 941150 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 911100, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920230, 920272, 920273 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 3 The pinned FTW stage prohibits CRS detection rule IDs 920230, 920272, 920273, 921151, 931130, 932190, 932200, 932370, 942200, 942430, 942431, 942432, 942440 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 3 The pinned FTW stage prohibits CRS detection rule IDs 920230, 920272, 920273, 931130, 932200, 932380, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920230, 920272, 920273, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920230, 920272, 920273, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 3 The pinned FTW stage prohibits CRS detection rule IDs 920230, 920273, 931130, 932190, 932235, 932236, 932350, 942421, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 3 The pinned FTW stage prohibits CRS detection rule IDs 920230, 932200, 932190, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920272 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 920420, 921110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 18 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 921110, 932236, 932250, 941100, 942120, 942210, 942340, 942390, 942432, 942450, 943120 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 921110, 941100, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 8 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 931100, 931130, 932200, 932240, 932220, 932236, 932240, 932260, 932350, 941170, 941210, 942200, 942430, 942431, 942432, 942440 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 931130, 932190, 932200, 932236, 932350, 932380, 942200, 942430, 942431, 942432, 942460 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 931130, 942430, 942431, 942432, 942440, 942460 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 932200, 932240, 942430, 942431, 942432, 942460 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 16 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 932236, 932350, 941100, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920273, 911100, 932350, 911100, 941100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920273, 920440, 930130 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920273, 921150, 931130, 932240, 942200, 942330, 942340, 942370, 942430, 942431, 942432, 942450 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 4 The pinned FTW stage prohibits CRS detection rule IDs 920273, 931130, 932190, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 931130, 932200, 932240, 941120, 941330, 941340, 942200, 942300, 942330, 942340, 942370, 942430, 942431, 942432, 942460, 942520 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920273, 931130, 932350, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932236, 932240, 932350, 942200, 942260, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 4 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932236, 932240, 942200, 942260, 942340, 942370, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932240 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932240, 942200, 942340, 942370, 942430, 942431, 942432, 942460 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932240, 942200, 942430, 942431, 942432, 942340, 942370, 942460, 942490 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932240, 942200, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932240, 942260, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 10 The pinned FTW stage prohibits CRS detection rule IDs 920273, 941100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 3 The pinned FTW stage prohibits CRS detection rule IDs 920273, 941100, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 6 The pinned FTW stage prohibits CRS detection rule IDs 920273, 941110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 941110, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 942290 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920273, 942430, 942431, 942432, 942440, 942460 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920274, 920450 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 26 The pinned FTW stage prohibits CRS detection rule IDs 920420 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920420, 920530 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920420, 921110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 7 The pinned FTW stage prohibits CRS detection rule IDs 920440 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920450 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 930120, 932160 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 930120, 932260, 932236, 932350, 941100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign ApplicationContent — 1 The pinned FTW stage prohibits CRS detection rule IDs 930120, 932260, 932236, 932350, 941100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification. The upstream plugin permits installer fields on any path. Clearplane's Nextcloud pack scopes the installer exclusions to the installer route, so <script> in adminpass and dbpass on an arbitrary endpoint stays blocked as XSS-shaped input.
crs-plugin-nextcloud — — Benign Benign — 9 The pinned FTW stage prohibits CRS detection rule IDs 931130 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 931130, 932190, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 9 The pinned FTW stage prohibits CRS detection rule IDs 932236 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 4 The pinned FTW stage prohibits CRS detection rule IDs 932236, 941100, 941120, 942390, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 14 The pinned FTW stage prohibits CRS detection rule IDs 941100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 7 The pinned FTW stage prohibits CRS detection rule IDs 942450 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 956110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-nextcloud command-injection command-injection Benign Attack — 1 The pinned FTW stage requires CRS detection rule IDs 920273, 920300, 932200, 932240. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category. Its expected rules start at paranoia level 2, so it counts toward attack coverage from that level.
crs-plugin-nextcloud command-injection command-injection Benign Attack — 1 The pinned FTW stage requires CRS detection rule IDs 920273, 932200, 932240. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category. Its expected rules start at paranoia level 2, so it counts toward attack coverage from that level.
crs-plugin-nextcloud command-injection command-injection Benign Attack — 12 The pinned FTW stage requires CRS detection rule IDs 932160. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category.
crs-plugin-nextcloud protocol protocol Benign Attack — 1 The pinned FTW stage requires CRS detection rule IDs 920273, 920300, 932200, 932240. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category. Its expected rules start at paranoia level 3, so it counts toward attack coverage from that level.
crs-plugin-nextcloud protocol protocol Benign Attack — 1 The pinned FTW stage requires CRS detection rule IDs 920273, 932200, 932240. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category. Its expected rules start at paranoia level 4, so it counts toward attack coverage from that level.
crs-plugin-nextcloud protocol protocol Benign Attack — 1 The pinned FTW stage requires CRS detection rule IDs 920300, 942431, 942432, 942460. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category. Its expected rules start at paranoia level 3, so it counts toward attack coverage from that level.
crs-plugin-nextcloud protocol protocol Benign Attack — 1 The pinned FTW stage requires CRS detection rule IDs 920320. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category. Its expected rules start at paranoia level 2, so it counts toward attack coverage from that level.
crs-plugin-nextcloud protocol protocol Benign Attack — 10 The pinned FTW stage requires CRS detection rule IDs 920420. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category.
crs-plugin-nextcloud sql-injection sql-injection Benign Attack — 1 The pinned FTW stage requires CRS detection rule IDs 920300, 942431, 942432, 942460. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category. Its expected rules start at paranoia level 3, so it counts toward attack coverage from that level.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920540 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 921140 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 932110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 932125 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 932180 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 932230, 932250 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 932235 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 932236, 932260 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 932260 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 932380 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 933150 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 941160 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 3 The pinned FTW stage prohibits CRS detection rule IDs 942100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 942140 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-phpmyadmin — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 942151 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 6 The pinned FTW stage prohibits CRS detection rule IDs 920100, 920273, 921220, 921180, 932236, 932350, 942360, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 10 The pinned FTW stage prohibits CRS detection rule IDs 920230, 932235, 932236, 942360, 942362, 942430, 942431, 942432, 942450 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 920650, 921180, 932200, 932240, 942370, 942430, 942431, 942432, 942520 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 921180, 932200, 932240, 942370, 942430, 942431, 942432, 942520 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 4 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 931130, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 5 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 932200, 932220, 932235, 932236, 942100, 942430, 942431, 942432, 942440 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 932200, 932236, 932240, 932370, 941150, 941180, 941181, 941320, 941330, 942130, 942131, 942200, 942210, 942260, 942330, 942340, 942370, 942430, 942431, 942432, 942440, 942460, 942520 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920272, 920273, 932200, 932240, 942370, 942430, 942431, 942432, 942520 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 920230, 932235, 932236, 942360, 942362, 942430, 942431, 942432, 942450 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 921220, 932100, 932130, 933210, 932231, 941100, 941160, 942432, 942460 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 930130, 932350, 932260, 932236, 941110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932235, 932236, 942120, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932236, 941110 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 4 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932236, 941110, 942430, 942431, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 920273, 932240, 931130, 941130, 942432 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 12 The pinned FTW stage prohibits CRS detection rule IDs 920450 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 930121 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 930130 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 931130 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 932130 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 9 The pinned FTW stage prohibits CRS detection rule IDs 932236 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 932240, 932236, 941100, 941150, 941160, 941180, 941181, 941320, 942210, 942330, 942340, 942370, 942430, 942431, 942432, 942440, 942520 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 942120 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 951240 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 1 The pinned FTW stage prohibits CRS detection rule IDs 953100 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress — — Benign Benign — 2 The pinned FTW stage prohibits CRS detection rule IDs 953101 and requires no CRS detection ID; it is a benign control. Plugin exclusion-rule IDs do not change that classification.
crs-plugin-wordpress command-injection command-injection Benign Attack — 2 The pinned FTW stage requires CRS detection rule IDs 932160. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category.
crs-plugin-wordpress remote-file-inclusion remote-file-inclusion Benign Attack — 1 The pinned FTW stage requires CRS detection rule IDs 931130. It is an attack control, including when the plugin source also contains benign exclusion tests. Multi-category controls retain one evaluation per expected category. Its expected rules start at paranoia level 2, so it counts toward attack coverage from that level.
crs-responses data-leakage data-leakage Attack Benign — 5 Pinned CRS 953101.yaml contains five ordinary prose probes explicitly described by upstream as false positives at PL1 (file size, invalid date, function, static function, empty field), plus one benign functionality control. All six backend bodies remain byte-for-byte unchanged. Treat these as benign disclosure controls independently of the PL2 detection expectation; the five upstream strict parity expectations remain failures in CRS replay.
crs-responses data-leakage data-leakage Benign Benign — 1 Pinned CRS 953101.yaml contains five ordinary prose probes explicitly described by upstream as false positives at PL1 (file size, invalid date, function, static function, empty field), plus one benign functionality control. All six backend bodies remain byte-for-byte unchanged. Treat these as benign disclosure controls independently of the PL2 detection expectation; the five upstream strict parity expectations remain failures in CRS replay.
crs-responses data-leakage data-leakage Benign Benign — 7 Pinned CRS no-expect response control supplies text/plain or text/html directly to Albedo /reflect, whose JSON contract rejects it. Preserve the intended benign text byte-for-byte as a direct response-body control; strict CRS replay remains skipped.
crs-responses data-leakage data-leakage Benign Benign — 6 Pinned CRS response stage prohibits a data-leakage detection. Backend bytes come from its explicit response or Albedo POST /reflect specification.
crs-responses data-leakage data-leakage Attack Attack — 71 Pinned CRS response stage requires a data-leakage detection. Backend bytes come from its explicit response or Albedo POST /reflect specification.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties are allowed by default; additional properties are allowed; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: additionalProperties being false does not allow other properties; an additional property is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties being false does not allow other properties; ignores arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties being false does not allow other properties; ignores other non-objects; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties being false does not allow other properties; ignores strings; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties being false does not allow other properties; no additional properties is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties being false does not allow other properties; patternProperties are not additional properties; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: additionalProperties can exist by itself; an additional invalid property is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties can exist by itself; an additional valid property is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: additionalProperties does not look in applicators; properties defined in allOf are not examined; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties with null valued instance properties; allows null values; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties with propertyNames; Valid against both keywords; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: additionalProperties with propertyNames; Valid against propertyNames, but not additionalProperties; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: additionalProperties with schema; an additional invalid property is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties with schema; an additional valid property is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: additionalProperties with schema; no additional properties is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf combined with anyOf, oneOf; allOf: false, anyOf: false, oneOf: false; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf combined with anyOf, oneOf; allOf: false, anyOf: false, oneOf: true; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf combined with anyOf, oneOf; allOf: false, anyOf: true, oneOf: false; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf combined with anyOf, oneOf; allOf: false, anyOf: true, oneOf: true; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf combined with anyOf, oneOf; allOf: true, anyOf: false, oneOf: false; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf combined with anyOf, oneOf; allOf: true, anyOf: false, oneOf: true; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf combined with anyOf, oneOf; allOf: true, anyOf: true, oneOf: false; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf combined with anyOf, oneOf; allOf: true, anyOf: true, oneOf: true; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf simple types; mismatch one; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf simple types; valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf with base schema; mismatch base schema; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf with base schema; mismatch both; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf with base schema; mismatch first allOf; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf with base schema; mismatch second allOf; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf with base schema; valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf with boolean schemas, all false; any value is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf with boolean schemas, all true; any value is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf with boolean schemas, some false; any value is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf with one empty schema; any data is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf with the first empty schema; number is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf with the first empty schema; string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf with the last empty schema; number is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf with the last empty schema; string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf with two empty schemas; any data is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allOf; allOf; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf; mismatch first; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf; mismatch second; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: allOf; wrong type; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; boolean false is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; boolean true is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; empty array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; empty object is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; null is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; number is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; object is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: allow everything with boolean schema false; string is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf complex types; both anyOf valid (complex); valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf complex types; first anyOf valid (complex); valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: anyOf complex types; neither anyOf valid (complex); valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf complex types; second anyOf valid (complex); valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: anyOf with base schema; both anyOf invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: anyOf with base schema; mismatch base schema; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf with base schema; one anyOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: anyOf with boolean schemas, all false; any value is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf with boolean schemas, all true; any value is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf with boolean schemas, some true; any value is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf with one empty schema; number is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf with one empty schema; string is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf; both anyOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf; first anyOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: anyOf; neither anyOf valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: anyOf; second anyOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: array type matches arrays; a boolean is not an array; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: array type matches arrays; a float is not an array; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: array type matches arrays; a string is not an array; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: array type matches arrays; an array is an array; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: array type matches arrays; an integer is not an array; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: array type matches arrays; an object is not an array; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: array type matches arrays; null is not an array; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: boolean type matches booleans; a float is not a boolean; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: boolean type matches booleans; a string is not a boolean; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: boolean type matches booleans; an array is not a boolean; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: boolean type matches booleans; an empty string is not a boolean; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: boolean type matches booleans; an integer is not a boolean; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: boolean type matches booleans; an object is not a boolean; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: boolean type matches booleans; false is a boolean; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: boolean type matches booleans; null is not a boolean; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: boolean type matches booleans; true is a boolean; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: boolean type matches booleans; zero is not a boolean; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: by int; ignores non-numbers; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: by int; int by int fail; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: by int; int by int; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: by number; -4.5 is multiple of 1.5; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: by number; 35 is not multiple of 1.5; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: by number; 4.5 is multiple of 1.5; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: by number; zero is multiple of anything; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: by small number; 0.0075 is multiple of 0.0001; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: by small number; 0.00751 is not multiple of 0.0001; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: characters with the same visual representation but different codepoint; character looks the same but uses a different codepoint; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: characters with the same visual representation but different codepoint; character uses the same codepoint; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 2 Independent JSON Schema assertion: characters with the same visual representation, but different number of codepoints; character looks the same but uses combining marks; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 2 Independent JSON Schema assertion: characters with the same visual representation, but different number of codepoints; character uses the same codepoint; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: collect annotations inside a 'not', even if collection is disabled; annotations are still collected inside a 'not'; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: collect annotations inside a 'not', even if collection is disabled; unevaluated property; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const validation; another type is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const validation; another value is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const validation; same value is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with -2.0 matches integer and float types; float -2.0 is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with -2.0 matches integer and float types; float -2.00001 is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with -2.0 matches integer and float types; float 2.0 is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with -2.0 matches integer and float types; integer -2 is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with -2.0 matches integer and float types; integer 2 is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with 0 does not match other zero-like types; empty array is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with 0 does not match other zero-like types; empty object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with 0 does not match other zero-like types; empty string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with 0 does not match other zero-like types; false is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with 0 does not match other zero-like types; float zero is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with 0 does not match other zero-like types; integer zero is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with 1 does not match true; float one is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with 1 does not match true; integer one is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with 1 does not match true; true is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with [false] does not match [0]; [0.0] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with [false] does not match [0]; [0] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with [false] does not match [0]; [false] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with [true] does not match [1]; [1.0] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with [true] does not match [1]; [1] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with [true] does not match [1]; [true] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with array; another array item is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with array; array with additional items is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with array; same array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with false does not match 0; false is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with false does not match 0; float zero is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with false does not match 0; integer zero is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with null; not null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with null; null is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with object; another object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with object; another type is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with object; same object is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with object; same object with different property order is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with true does not match 1; float one is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with true does not match 1; integer one is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with true does not match 1; true is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with {"a": false} does not match {"a": 0}; {"a": 0.0} is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with {"a": false} does not match {"a": 0}; {"a": 0} is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with {"a": false} does not match {"a": 0}; {"a": false} is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with {"a": true} does not match {"a": 1}; {"a": 1.0} is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: const with {"a": true} does not match {"a": 1}; {"a": 1} is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: const with {"a": true} does not match {"a": 1}; {"a": true} is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: dependentSchemas with additionalProperties; additionalProperties can't see bar even when foo2 is present; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: dependentSchemas with additionalProperties; additionalProperties can't see bar; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: dependentSchemas with additionalProperties; additionalProperties doesn't consider dependentSchemas; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: double negation; any value is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: empty enum; array is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: empty enum; boolean is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: empty enum; null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: empty enum; number is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: empty enum; object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: empty enum; string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with 0 does not match false; false is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with 0 does not match false; float zero is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with 0 does not match false; integer zero is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with 1 does not match true; float one is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with 1 does not match true; integer one is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with 1 does not match true; true is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with [0] does not match [false]; [0.0] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with [0] does not match [false]; [0] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with [0] does not match [false]; [false] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with [1] does not match [true]; [1.0] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with [1] does not match [true]; [1] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with [1] does not match [true]; [true] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with [false] does not match [0]; [0.0] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with [false] does not match [0]; [0] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with [false] does not match [0]; [false] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with [true] does not match [1]; [1.0] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with [true] does not match [1]; [1] is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with [true] does not match [1]; [true] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with escaped characters; another string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with escaped characters; member 1 is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with escaped characters; member 2 is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with false does not match 0; false is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with false does not match 0; float zero is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with false does not match 0; integer zero is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with true does not match 1; float one is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enum with true does not match 1; integer one is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enum with true does not match 1; true is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enums in properties; both properties are valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enums in properties; missing all properties is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: enums in properties; missing optional property is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enums in properties; missing required property is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enums in properties; wrong bar value; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: enums in properties; wrong foo value; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: exclusiveMaximum validation; above the exclusiveMaximum is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: exclusiveMaximum validation; below the exclusiveMaximum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: exclusiveMaximum validation; boundary point is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: exclusiveMaximum validation; ignores non-numbers; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: exclusiveMinimum validation; above the exclusiveMinimum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: exclusiveMinimum validation; below the exclusiveMinimum is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: exclusiveMinimum validation; boundary point is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: exclusiveMinimum validation; ignores non-numbers; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: float and integers are equal up to 64-bit representation limits; float is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: float and integers are equal up to 64-bit representation limits; float minus one is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: float and integers are equal up to 64-bit representation limits; integer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: float and integers are equal up to 64-bit representation limits; integer minus one is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: float division = inf; always invalid, but naive implementations may raise an overflow error; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; array is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; boolean false is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; boolean true is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; empty array is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; empty object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; number is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with boolean schema true; string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; array is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; boolean false is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; boolean true is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; empty array is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; empty object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; number is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbid everything with empty schema; string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: forbidden property; property absent; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: forbidden property; property present; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: heterogeneous enum validation; extra properties in object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: heterogeneous enum validation; objects are deep compared; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: heterogeneous enum validation; one of the enum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: heterogeneous enum validation; something else is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: heterogeneous enum validation; valid object matches; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: heterogeneous enum-with-null validation; null is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: heterogeneous enum-with-null validation; number is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: heterogeneous enum-with-null validation; something else is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: integer type matches integers; a boolean is not an integer; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: integer type matches integers; a float is not an integer; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: integer type matches integers; a float with zero fractional part is an integer; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: integer type matches integers; a string is not an integer; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: integer type matches integers; a string is still not an integer, even if it looks like one; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: integer type matches integers; an array is not an integer; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: integer type matches integers; an integer is an integer; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: integer type matches integers; an object is not an integer; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: integer type matches integers; null is not an integer; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxItems validation with a decimal; shorter is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maxItems validation with a decimal; too long is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxItems validation; exact length is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxItems validation; ignores non-arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxItems validation; shorter is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maxItems validation; too long is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxLength validation with a decimal; shorter is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maxLength validation with a decimal; too long is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxLength validation; exact length is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxLength validation; ignores non-strings; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxLength validation; shorter is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maxLength validation; too long is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxLength validation; two graphemes is long enough; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxProperties = 0 means the object is empty; no properties is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maxProperties = 0 means the object is empty; one property is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxProperties validation with a decimal; shorter is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maxProperties validation with a decimal; too long is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxProperties validation; exact length is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxProperties validation; ignores arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxProperties validation; ignores other non-objects; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxProperties validation; ignores strings; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maxProperties validation; shorter is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maxProperties validation; too long is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maximum validation with unsigned integer; above the maximum is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maximum validation with unsigned integer; below the maximum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maximum validation with unsigned integer; boundary point float is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maximum validation with unsigned integer; boundary point integer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: maximum validation; above the maximum is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maximum validation; below the maximum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maximum validation; boundary point is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: maximum validation; ignores non-numbers; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minItems validation with a decimal; longer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minItems validation with a decimal; too short is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minItems validation; exact length is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minItems validation; ignores non-arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minItems validation; longer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minItems validation; too short is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minLength validation with a decimal; longer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minLength validation with a decimal; too short is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minLength validation; exact length is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minLength validation; ignores non-strings; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minLength validation; longer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minLength validation; one grapheme is not long enough; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minLength validation; too short is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minProperties validation with a decimal; longer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minProperties validation with a decimal; too short is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minProperties validation; exact length is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minProperties validation; ignores arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minProperties validation; ignores booleans; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minProperties validation; ignores null; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minProperties validation; ignores other non-objects; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minProperties validation; ignores strings; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minProperties validation; longer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minProperties validation; too short is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minimum validation with signed integer; boundary point is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minimum validation with signed integer; boundary point with float is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minimum validation with signed integer; float below the minimum is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minimum validation with signed integer; ignores non-numbers; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minimum validation with signed integer; int below the minimum is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minimum validation with signed integer; negative above the minimum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minimum validation with signed integer; positive above the minimum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minimum validation; above the minimum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: minimum validation; below the minimum is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minimum validation; boundary point is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: minimum validation; ignores non-numbers; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: multiple types can be specified in an array; a boolean is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: multiple types can be specified in an array; a float is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: multiple types can be specified in an array; a string is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: multiple types can be specified in an array; an array is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: multiple types can be specified in an array; an integer is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: multiple types can be specified in an array; an object is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: multiple types can be specified in an array; null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: nested allOf, to check validation semantics; anything non-null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: nested allOf, to check validation semantics; null is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: nested anyOf, to check validation semantics; anything non-null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: nested anyOf, to check validation semantics; null is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: nested oneOf, to check validation semantics; anything non-null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: nested oneOf, to check validation semantics; null is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: non-ASCII pattern with additionalProperties; matching the pattern is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: non-ASCII pattern with additionalProperties; not matching the pattern is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: not more complex schema; match; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: not more complex schema; mismatch; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: not more complex schema; other match; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: not multiple types; mismatch; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: not multiple types; other mismatch; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: not multiple types; valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: not; allowed; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: not; disallowed; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 2 Independent JSON Schema assertion: nul characters in strings; do not match string lacking nul; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack ApplicationContent — 2 Independent JSON Schema assertion: nul characters in strings; match string with nul; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent. The valid document carries NUL characters or control characters in property names, which the default rulesets block as injection-shaped input.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; a float is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; a string is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; an array is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; an empty string is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; an integer is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; an object is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; false is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: null type matches only the null object; null is null; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; true is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: null type matches only the null object; zero is not null; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: number type matches numbers; a boolean is not a number; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: number type matches numbers; a float is a number; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: number type matches numbers; a float with zero fractional part is a number (and an integer); valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: number type matches numbers; a string is not a number; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: number type matches numbers; a string is still not a number, even if it looks like one; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: number type matches numbers; an array is not a number; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: number type matches numbers; an integer is a number; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: number type matches numbers; an object is not a number; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: number type matches numbers; null is not a number; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: object properties validation; both properties invalid is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: object properties validation; both properties present and valid is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: object properties validation; doesn't invalidate other properties; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: object properties validation; ignores arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: object properties validation; ignores other non-objects; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: object properties validation; one property invalid is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: object type matches objects; a boolean is not an object; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: object type matches objects; a float is not an object; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: object type matches objects; a string is not an object; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: object type matches objects; an array is not an object; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: object type matches objects; an integer is not an object; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: object type matches objects; an object is an object; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: object type matches objects; null is not an object; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf complex types; both oneOf valid (complex); valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf complex types; first oneOf valid (complex); valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf complex types; neither oneOf valid (complex); valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf complex types; second oneOf valid (complex); valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with base schema; both oneOf valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with base schema; mismatch base schema; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf with base schema; one oneOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with boolean schemas, all false; any value is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with boolean schemas, all true; any value is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with boolean schemas, more than one true; any value is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf with boolean schemas, one true; any value is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with empty schema; both valid - invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf with empty schema; one valid - valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with missing optional property; both oneOf valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf with missing optional property; first oneOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with missing optional property; neither oneOf valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf with missing optional property; second oneOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with required; both invalid - invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf with required; both valid - invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf with required; first valid - valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf with required; second valid - valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf; both oneOf valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf; first oneOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: oneOf; neither oneOf valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: oneOf; second oneOf valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties whose names are Javascript object property names; __proto__ not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties whose names are Javascript object property names; all present and valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties whose names are Javascript object property names; constructor not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties whose names are Javascript object property names; ignores arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties whose names are Javascript object property names; ignores other non-objects; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties whose names are Javascript object property names; none of the properties mentioned; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties whose names are Javascript object property names; toString not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties with boolean schema; both properties present is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties with boolean schema; no property present is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties with boolean schema; only 'false' property present is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties with boolean schema; only 'true' property present is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack ApplicationContent — 1 Independent JSON Schema assertion: properties with escaped characters; object with all numbers is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent. The valid document carries NUL characters or control characters in property names, which the default rulesets block as injection-shaped input.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties with escaped characters; object with strings is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties with null valued instance properties; allows null values; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties, patternProperties, additionalProperties interaction; additionalProperty ignores property; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties, patternProperties, additionalProperties interaction; additionalProperty invalidates others; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties, patternProperties, additionalProperties interaction; additionalProperty validates others; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties, patternProperties, additionalProperties interaction; patternProperty invalidates nonproperty; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties, patternProperties, additionalProperties interaction; patternProperty invalidates property; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties, patternProperties, additionalProperties interaction; patternProperty validates nonproperty; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: properties, patternProperties, additionalProperties interaction; property invalidates property; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: properties, patternProperties, additionalProperties interaction; property validates property; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required default validation; not required by default; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: required properties whose names are Javascript object property names; __proto__ present; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required properties whose names are Javascript object property names; all present; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: required properties whose names are Javascript object property names; constructor present; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required properties whose names are Javascript object property names; ignores arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required properties whose names are Javascript object property names; ignores other non-objects; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: required properties whose names are Javascript object property names; none of the properties mentioned; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: required properties whose names are Javascript object property names; toString present; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required validation; ignores arrays; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required validation; ignores boolean; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required validation; ignores null; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required validation; ignores other non-objects; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required validation; ignores strings; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: required validation; non-present required property is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required validation; present required property is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: required with empty array; property not required; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack ApplicationContent — 1 Independent JSON Schema assertion: required with escaped characters; object with all properties present is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent. The valid document carries NUL characters or control characters in property names, which the default rulesets block as injection-shaped input.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: required with escaped characters; object with some properties missing is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: simple enum validation; one of the enum is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: simple enum validation; something else is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: small multiple of large integer; any integer is a multiple of 1e-8; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: string type matches strings; 1 is not a string; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: string type matches strings; a boolean is not a string; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: string type matches strings; a float is not a string; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: string type matches strings; a string is a string; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: string type matches strings; a string is still a string, even if it looks like a number; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: string type matches strings; an array is not a string; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: string type matches strings; an empty string is still a string; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: string type matches strings; an object is not a string; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: string type matches strings; null is not a string; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: type as array with one item; number is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: type as array with one item; string is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: type: array or object; array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: type: array or object; null is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: type: array or object; number is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: type: array or object; object is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: type: array or object; string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: type: array, object or null; array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: type: array, object or null; null is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: type: array, object or null; number is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: type: array, object or null; object is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: type: array, object or null; string is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; 0 and false are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; 1 and true are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; [0] and [false] are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; [1] and [true] are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; different objects are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; false is not equal to zero; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; nested [0] and [false] are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; nested [1] and [true] are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; non-unique array of arrays is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; non-unique array of integers is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; non-unique array of more than two arrays is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; non-unique array of more than two integers is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; non-unique array of nested objects is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; non-unique array of objects is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; non-unique array of strings is invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; non-unique heterogeneous types are invalid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; numbers are unique if mathematically unequal; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; objects are non-unique despite key order; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems validation; property order of array of objects is ignored; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; true is not equal to one; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; unique array of arrays is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; unique array of integers is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; unique array of nested objects is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; unique array of objects is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; unique array of strings is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; unique heterogeneous types are valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; {"a": false} and {"a": 0} are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems validation; {"a": true} and {"a": 1} are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems with an array of items and additionalItems=false; [false, false] from items array is not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems with an array of items and additionalItems=false; [false, true] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems with an array of items and additionalItems=false; [true, false] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems with an array of items and additionalItems=false; [true, true] from items array is not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems with an array of items and additionalItems=false; extra items are invalid even if unique; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems with an array of items; [false, false] from items array is not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems with an array of items; [false, true] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems with an array of items; [true, false] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems with an array of items; [true, true] from items array is not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems with an array of items; non-unique array extended from [false, true] is not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems with an array of items; non-unique array extended from [true, false] is not valid; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems with an array of items; unique array extended from [false, true] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems with an array of items; unique array extended from [true, false] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; 0 and false are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; 1 and true are unique; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; false is not equal to zero; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; non-unique array of arrays is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; non-unique array of integers is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; non-unique array of nested objects is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; non-unique array of objects is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; non-unique heterogeneous types are valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; numbers are unique if mathematically unequal; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; true is not equal to one; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; unique array of arrays is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; unique array of integers is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; unique array of nested objects is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; unique array of objects is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false validation; unique heterogeneous types are valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items and additionalItems=false; [false, false] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items and additionalItems=false; [false, true] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items and additionalItems=false; [true, false] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items and additionalItems=false; [true, true] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Attack — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items and additionalItems=false; extra items are invalid even if unique; valid=false. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items; [false, false] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items; [false, true] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items; [true, false] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items; [true, true] from items array is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items; non-unique array extended from [false, true] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items; non-unique array extended from [true, false] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items; unique array extended from [false, true] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
json-schema-test-suite api-schema api-schema Attack Benign — 1 Independent JSON Schema assertion: uniqueItems=false with an array of items; unique array extended from [true, false] is valid; valid=true. Invalid denotes a request that violates its configured schema, not malicious intent.
payloads-all-the-things ldap-injection ldap-injection Attack Benign — 54 Bare LDAP attribute names are benign data. The pinned README lists them as Defaults Attributes and interpolates them into filter syntax for attacks.
payloads-all-the-things ldap-injection ldap-injection Attack Attack — 98 The LDAP README defines authentication bypass by interpolating user input into a login filter. Preserve payload bytes in a named login parameter; no filter wrapper or successful detection is required for classification.
payloads-all-the-things ldap-injection ldap-injection Attack Attack — 54 The pinned LDAP Injection README uses each attribute in the filter-breaking login template *)(=*)) followed by NUL; bare attribute names are not injections.
payloads-all-the-things ldap-injection ldap-injection Attack Benign — 28 This complete value contains no LDAP filter assertion metacharacter (asterisk, parentheses, backslash or NUL). Slash and literal boolean-operator characters inside an assertion value do not change RFC4515 filter syntax; retain it as a benign regression.
payloads-all-the-things open-redirect open-redirect Attack Attack — 211 Standalone destinations are placed in the redirect query parameter, matching the pinned Open Redirect README Common Query Parameters.
payloads-all-the-things open-redirect open-redirect Attack Benign open-redirect 50 This destination remains a same-origin relative path for both HTTP and HTTPS localhost bases, including zero, one and two percent-decoding passes where valid, under independent Node WHATWG URL parsing. Preserve it as a benign off-origin regression; no undocumented server rewrite is assumed.
payloads-all-the-things open-redirect open-redirect Attack Attack — 12 This source line is a complete request target with its own redirect parameters. Preserve that query instead of encoding the entire target inside one parameter; see the pinned README redirect?url= example.
payloads-all-the-things open-redirect open-redirect Attack Benign open-redirect 48 Under the original HTTP request origin, this same-scheme no-slash URL is a relative path under WHATWG special-relative-or-authority parsing. Retain this HTTP control and add a separate HTTPS-origin attack/probe from the same exact source bytes.
payloads-all-the-things xxe php-injection Attack Attack — 3 PHP code execution or an XSLT PHP extension invocation; it remains an attack in its original XML body and does not declare or resolve an external XML entity.
payloads-all-the-things xxe sql-injection Attack Attack — 3 Boolean SQL injection text carried inside XML CDATA; it remains an attack in its original XML body and does not declare or resolve an external XML entity.
payloads-all-the-things ldap-injection xpath-injection Attack Attack — 6 This quoted boolean/name() expression is XPath injection syntax, not LDAP filter syntax; retain its Attack role and bytes.
payloads-all-the-things xxe xpath-injection Attack Attack — 4 XPath query probing or a boolean XPath breakout; it remains an attack in its original XML body. XPath injection semantics: https://owasp.org/www-community/attacks/XPATH_Injection
payloads-all-the-things xxe xss Attack Attack — 37 Browser script, script-context breakout or legacy XML data-island XSS vector; it remains an attack in its original XML body. XSS semantics: https://cheatsheetseries.owasp.org/cheatsheets/XSS_Filter_Evasion_Cheat_Sheet.html#xml-data-island-with-cdata-obfuscation
payloads-all-the-things open-redirect xss Attack Attack — 4 The destination uses a script/data scheme rather than another web origin; retain it as an XSS attack in the original named redirect parameter. Classification follows WHATWG URL parsing independently of WAF matches.
payloads-all-the-things xxe xxe Attack Benign — 2 The line contains only literal Unicode punctuation and no executable, DTD or entity syntax. XML semantics: https://www.w3.org/TR/xml/#sec-cdata-sect
payloads-all-the-things xxe xxe Attack Benign — 7 The line contains only ordinary XML markup, an XML declaration, predefined character references or a plain-text CDATA section; it has no DTD, custom entity or executable construct. XML semantics: https://www.w3.org/TR/xml/#sec-cdata-sect
payloads-all-the-things-core command-injection command-injection Attack Attack — 160 Published command-injection probes inserted as an application command argument through query and form input; original bytes, quoting and encodings are preserved.
payloads-all-the-things-core path-traversal command-injection Attack Attack — 8 The payload invokes /bin/cat using line or quote injection and contains no directory traversal segment. Preserve its attack role as command injection.
payloads-all-the-things-core path-traversal path-traversal Attack Attack — 272 Published traversal and sensitive-file read probes inserted as an application file path through query and form input; original bytes and encodings are preserved.
payloads-all-the-things-core command-injection php-injection Attack Attack — 6 The payload calls PHP system() using PHP expression syntax, rather than a shell command separator plus a program. Preserve its attack role with PHP injection attribution.
payloads-all-the-things-core protocol protocol Attack Attack — 34 Complete published CRLF response-header injection list supplied through query and form input reflected by an application into an HTTP header, as described in the pinned CRLF README; raw transport-invalid requests are not substituted for these application inputs.
payloads-all-the-things-core xss xss Attack ApplicationContent — 2 A heading element alone contains no executable script, event handler, navigation or script-context escape, but it is an HTML injection probe. Markup is application content: the default rulesets block it and rich-text applications opt out with an exclusion ruleset.
payloads-all-the-things-core xss xss Attack Attack — 32 Complete published XSS polyglot list supplied through query and form input for downstream HTML/attribute/script interpolation; original bytes are preserved.
payloads-all-the-things-core xss xss Attack Attack — 76 Published script-injection probes supplied through query and form input to an HTML, attribute or inline-script interpolation context; no browser execution is performed.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 1 Published Json.NET ObjectDataProvider payload retains single-quoted JSON accepted by Json.NET; submit raw bytes without normalizing the document.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 3 Published PHP deserialization authentication bypass using boolean coercion or aliased references; retain attacks requiring application semantics.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 1 Published PHP object injection payload supplied in serialized input context.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 1 Published Ruby Marshal gadget byte sequence, decoded from its documented hexadecimal representation without executing it.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 3 Published Ruby YAML universal deserialization gadget; submit the complete YAML document unchanged.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 1 Published SnakeYAML ScriptEngineManager and URLClassLoader construction gadget.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 1 Published XmlSerializer ObjectDataProvider execution gadget, excluding the generator command.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 2 Published multi-line unsafe YAML execution gadget; complete document preserved.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 2 Published serialized immediately invoked function gadget for node-serialize or funcster; complete JSON body preserved.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 6 Published unsafe YAML dynamic object construction example; full source tag and arguments preserved.
payloads-all-the-things-examples deserialization deserialization Attack ApplicationContent — 1 Source explicitly labels this PHP array as normal serialization output; it contains strings and no object construction. Serialized data in a cookie is still deserialization-shaped application content: the default rulesets block it and applications that store serialized cookies opt out with an exclusion ruleset.
payloads-all-the-things-examples deserialization deserialization Attack Attack — 5 The source identifies this JSON polymorphic type as an unsafe deserialization gadget; preserve its published type and value bytes, including documented placeholders.
payloads-all-the-things-examples graphql graphql Attack Attack — 3 Published schema introspection/enumeration request; production policy prohibits schema disclosure, while ordinary application queries remain benign.
payloads-all-the-things-examples graphql graphql Attack Attack — 1 Source explicitly describes password brute-force amplification using repeated login aliases; preserve its four attempts even below the current generic alias cap.
payloads-all-the-things-examples graphql graphql Attack Attack — 1 Source introspection query in production schema-disclosure policy context; GraphQL itself permits this feature.
payloads-all-the-things-examples graphql graphql Attack Benign — 4 Source ordinary query example retrieves a user and related fields without schema introspection or amplification.
payloads-all-the-things-examples graphql graphql Attack Benign — 2 Source ordinary sign-in or user creation mutation; operation type alone is not an attack.
payloads-all-the-things-examples jwt jwt Attack Attack — 1 Published RSA-to-HMAC key-confusion forged JWT. Its header and signature are syntactically ordinary; detecting this attack requires issuer algorithm/key policy, so retain the measurement miss.
payloads-all-the-things-examples jwt jwt Attack Attack — 1 Published null-signature authentication bypass compact JWT; no signature is added by the adapter.
payloads-all-the-things-examples jwt jwt Attack Benign — 1 The token format section gives this ordinary signed JWT as a structural example; signature validity requires issuer keys outside this traffic.
payloads-all-the-things-examples nosql-injection nosql-injection Attack Attack — 1 Source identifies embedded NoSQL query operator injection in a GraphQL argument; preserve GraphQL transport and expected injection category.
payloads-all-the-things-examples open-redirect open-redirect Attack Attack — 48 Published no-slash HTTP redirect bypass requires a different HTTPS origin to enter authority parsing. Exact source bytes retained; invalid authority probes remain attacks and are not dropped when WHATWG rejects them.
payloads-all-the-things-examples prototype-pollution prototype-pollution Attack Attack — 3 Published HTTP URL query pollution payload; extract only its query component, preserving percent encoding.
payloads-all-the-things-examples prototype-pollution prototype-pollution Attack Attack — 4 Published parameter pollution path supplied as a query assignment; retain bracket and dotted syntax.
payloads-all-the-things-examples prototype-pollution prototype-pollution Attack Attack — 2 Published prototype pollution JSON payload; preserve dotted and object property forms.
payloads-all-the-things-examples prototype-pollution prototype-pollution Attack Attack — 4 Published server-side prototype pollution JSON request; preserve object nesting and property names.
payloads-all-the-things-examples sql-injection sql-injection Attack Attack — 1 Source explicit stacked SQL statement and delay injection inside GraphQL; category follows injection semantics.
payloads-all-the-things-examples ssrf ssrf Attack Attack — 53 Published SSRF bypass/exploitation URL in an outbound fetch parameter. Retain URL parser and redirect-dependent cases without resolving DNS or following redirects.
payloads-all-the-things-examples ssrf ssrf Attack Benign — 1 Published Unicode spelling of a public example.com host; encoding alone is not an internal destination.
scanner-defaults-feroxbuster scanner scanner Attack Attack — 1 The pinned generated shell-completion description states this exact default User-Agent. This tests the declared scanner fingerprint, not hidden or randomized scanner identities.
scanner-defaults-feroxbuster scanner scanner Attack Attack — 1 The pinned scan-state integration fixture supplies this exact configured User-Agent for its real scan requests. This tests the declared scanner fingerprint, not hidden or randomized scanner identities.
scanner-defaults-ffuf scanner scanner Attack Attack — 5 Complete TestSelectVersion decision table: combine its expected version with the default User-Agent format in pinned pkg/runner/simple.go. This measures a declared security-tool fingerprint, not all scanning behavior; no upstream code is executed.
scanner-defaults-gobuster scanner scanner Attack Attack — 1 Pinned libgobuster/helpers.go DefaultUserAgent combines gobuster/ with this declared VERSION constant. This is a tool fingerprint; operators may explicitly authorize their own scanner traffic.
synthetic-benign — — Benign ApplicationContent — 15 Source code, markup and SQL statements are attack-shaped input that only authoring, developer and database applications accept. The default rulesets block them; such applications opt out with an exclusion ruleset or by disabling rulesets for their routes.

Skipped tests

The report records 119 skipped tests. Reasons include unsupported replay semantics, explicit exclusions, and requests that cannot be reconstructed. These are separate from unsupported expected source rule IDs in the CRS tables.

Source Reason Tests
crs AutocompleteHeadersDisabled 19
crs KestrelRejectsRequest 15
crs Listed 8
crs LogTextExpectation 48
crs ResponseSide 10
crs StatusOnlyExpectation 17
crs UnsupportedDataTemplate 2

Failure records

The report contains 1019 failure records, grouped below. BudgetExceeded and BodyUninspected record incomplete evaluation separately at every affected paranoia level, even when a category matched. BudgetExceeded includes exhausted parser, engine work and retained-finding limits. IncompleteBlocked records an attack whose inspection was incomplete but which is still blocked in Prevention, either because a rule in its category reached the threshold or because the exhausted budget fails closed; it does not make a category unmeasured. These are diagnostic records, not additional cases or a denominator for the rates above; the JSON report retains individual test IDs.

Source Kind Records
crs IncompleteBlocked 31
crs Missed 27
crs-plugin-nextcloud BudgetExceeded 2
crs-plugin-wordpress BudgetExceeded 2
crs-plugin-wordpress Missed 1
payloads-all-the-things IncompleteBlocked 12
payloads-all-the-things Missed 782
payloads-all-the-things-core Missed 14
payloads-all-the-things-examples Missed 148