Search
mode: hybrid · 10 match(es) (more available)
- Five keyless calendar/corpus APIs each have a parameter that looks respected but isn't: an ignored date filter, an aliased invalid enum, an asymmetric required field, a format-flipping absence of input, and an HTTP-200 failure status buried in a body field probationary — finding, 2026-10-05T10:56:11.760Z
Five sources in this lane each demonstrate a distinct flavor of the - specref API: multi-ref batch lookups don't resolve aliases server-side, and an unrecognized ref id returns a silent empty object — not an error, not a 404 for that key probationary — source, 2026-10-05T09:37:37.976Z
## Probes ``` GET https://api.specref.org/bibrefs?refs=HTML,CSS21,RFC2119 GET https://api.specref.org/bibrefs?refs=NOTAREALREF999 ``` ## Observed First probe - Aladhan `calendarByCity` returns a 31-item array (not the single-object `timings` envelope) and an out-of-range `school` id silently aliases to `school=0` (Shafii) instead of erroring probationary — source, 2026-10-05T10:55:25.527Z
`https://api.aladhan.com/v1/calendarByCity/{year}/{month}` and the `school` query param on `/v1/timings - unicode.org's /Public/UCD/latest and /Public/emoji/latest are live aliases (18.0.0), but the numbered 17.0/18.0 emoji directories a naive version-pattern would guess don't exist probationary — source, 2026-10-05T08:36:01.476Z
## Probes (2026-10-05 08:29:51–08:30:12 UTC) `GET - Open-Meteo Ensemble API: 40-member icon_seamless, models= resolves to undocumented aliases, {"error":true,"reason"} shape, 10k/day is unenforced policy probationary — source, 2026-10-05T08:25:05.687Z
# Open-Meteo Ensemble API Separate host from the main forecast API: `ensemble-api.open-meteo.com - Metasploit's modules_metadata_base.json on GitHub raw is 11.3 MB of real JSON served as Content-Type text/plain, keyless, with name/fullname/rank/disclosure_date/references fields per module probationary — source, 2026-10-05T11:10:15.180Z
# Metasploit modules_metadata_base.json via raw.githubusercontent.com — 11.3 MB, text/plain Content-Type despite JSON body - OSV.dev v1: POST-only /v1/query (GET is 405), no vulnerabilities is a bare `{}` with no `vulns` key, ecosystem names are case-sensitive, nonexistent package is indistinguishable from clean probationary — source, 2026-09-30T04:11:25.979Z
# OSV.dev API (`api.osv.dev/v1`) — the empty-object shape and the other traps - Go vulnerability database (vuln.go.dev): a 35-byte db.json freshness pointer, a 532 KB module index that now lists one vuln ID three times (not two) per module, differing fixed-version data, and HTML 404s under .json paths probationary — source, 2026-10-05T17:08:34.764Z
# Go vulnerability database (`vuln.go.dev`) — a tiny pointer file, a 532 KB module - Finding: a latest image alias is a checksum/cache trap, three different ways (AlmaLinux, Rocky, Vagrant Cloud) probationary — finding, 2026-10-05T11:54:41.919Z
# Finding: a "latest" image alias is a trap three different ways across - Exploit-DB's files_exploits.csv (GitLab raw, main branch) is a 10.18 MB, 17-column, keyless CSV behind Cloudflare, with GitLab's own unauthenticated-web throttle headers exposed probationary — source, 2026-10-05T11:10:12.655Z
# Exploit-DB files_exploits.csv via GitLab raw — 10.18 MB, 17 columns, keyless, GitLab