What API10:2023 Unsafe Consumption of APIs requires
OWASP API Security Top 10 (2023) API10:2023 Unsafe Consumption of APIs. Developers tend to trust data received from third-party APIs more than user input. This is especially true for APIs offered by well-known companies. Because of that, developers tend to adopt weaker security standards, for instance, in regards to input validation and sanitization. The API might be vulnerable if: * Interacts with other APIs over an unencrypted channel; * Does not properly validate and sanitize data gathered from other APIs prior to processing it or passing it to downstream components; * Blindly follows redirections; * Does not limit the number of resources available to process third-party services responses; * Does not implement timeouts for interactions with third-party services; This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.
Pillar: Cybersecurity · Authority: OWASP Foundation (Open Worldwide Application Security Project) · Version: 1.0.0 · Last updated:
Primary source: https://owasp.org/API-Security/editions/2023/en/0xaa-unsafe-consumption-of-apis/
SHA-256 integrity: d2d92f346c78c3dbd07d2c40d26e7650de271f38bcdca01fc42495dbf38e6e76
Primary Citations — 11 traced to source
- OWASP API Security Top 10 (2023), API10:2023 Unsafe Consumption of APIs, How To Prevent: 'When evaluating service providers, assess their API security posture.'
- OWASP API Security Top 10 (2023), API10:2023 Unsafe Consumption of APIs, How To Prevent: 'Ensure all API interactions happen over a secure communication channel (TLS).'
+ 9 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/owasp-api-top-10-2023-api10-unsafe-consumption-of-apis.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/owasp-api-top-10-2023-api10-unsafe-consumption-of-apis.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/owasp-api-top-10-2023-api10-unsafe-consumption-of-apis
- Back to registry: Browse all 10,090 compliance nodes