# Integer Overflow or Wraparound (CWE-190) The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. **Stack:** Python - Prevalence: Media 3 lenguajes cubiertos - Impact: Medio Se recomienda revisión - Prevention: Documentada 3 ejemplos de corrección **OWASP:** Security Misconfiguration (A05:2021-Security Misconfiguration) - #5 ## Description An integer overflow occurs when an arithmetic operation attempts to create a numeric value that is outside of the range that can be represented with a given number of bits. This can lead to buffer overflows, incorrect financial calculations, or security bypasses. ## Prevention Estrategias de prevención para Integer Overflow basadas en 1 reglas de detección de Shoulder. ### Python Validate numeric bounds before arithmetic operations on user input ## Warning Signs - [LOW] potential integer overflow in numeric operations ## Consequences - DoS - Ejecutar código no autorizado - Modificar datos de la aplicación ## Mitigations - Usa lenguajes o bibliotecas que verifiquen el desbordamiento de enteros - Verifica que las entradas estén dentro de los rangos esperados - Usa funciones aritméticas seguras que verifiquen el desbordamiento ## Detection - Total rules: 3 - Languages: go, javascript, typescript, python ## Rules by Language ### Python (1 rules) - **Integer Overflow / Large Number Handling** [LOW]: Detects potential integer overflow in numeric operations. - Remediation: Validate numeric bounds before arithmetic operations. ```python from flask import request, jsonify @app.route('/calculate') def calculate(): count = int(request.args.get('count', 0)) if count < 0 or count > 10000: return jsonify({'error': 'Invalid count'}), 400 result = count * unit_price return jsonify({'total': result}) ``` Learn more: https://shoulder.dev/learn/python/cwe-190/integer-overflow