Maximum numeric value is undefined (OpenAPI 3.0)

A numeric field that needs an upper bound lacks a maximum constraint

Description

If a numeric field such as a quantity or amount needs an upper bound, omitting maximum or an equivalent constraint can allow values outside the permitted business range to pass schema validation.

Potential impact

If the server also omits the upper-bound check, excessively large values may cause calculation errors or processing failures.

Remediation

Define maximum according to the permitted range and enforce the same limit on the server. Check whether a list of allowed values or a referenced schema already supplies the upper bound.

Examples

This OpenAPI 3.0 excerpt adds a maximum of 50 to the existing minimum of 0 for code. The value 50 is the business limit chosen for this example.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "schemas": {
      "GeneralError": {
        "type": "object",
        "properties": {
          "code": {
            "type": "integer",
            "format": "int32",
            "minimum": 0
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "schemas": {
      "GeneralError": {
        "type": "object",
        "properties": {
          "code": {
            "type": "integer",
            "format": "int32",
            "minimum": 0,
            "maximum": 50
          }
        }
      }
    }
  }
}

References