Unbounded requests consume compute, memory or downstream capacity.
Use this profile to understand the building block briefly, place it in the model, and open related building blocks.
Theoretical construct: explains a term, principle, or mental model.
Concrete cog in the system that works inside larger relationships.
API resource exhaustion is the overloading of CPU, memory, network, file, or cost budgets by unbounded API requests.
OWASP introduced Unrestricted Resource Consumption as API4:2023 in the API Security Top 10. The approach grew from recurring observations that missing limits on request counts, payloads, execution time, or response size can cause denial of service and unexpected costs.
Every request consumes a finite budget. Without rate, size, timeout, and spending limits, one client can trigger enough expensive work to starve the service for other users.
Requests receive limits for size, frequency, time, and result volume.
Overloaded resources are no longer available to legitimate requests.
Unbounded third-party calls can exhaust financial budgets too.
The pattern directs API design toward measurable consumption limits that protect availability and operating cost.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.