Unsafe consumption of APIs
Data coming back from a third-party API is input from outside, and teams routinely treat it as trusted because they chose the supplier.
The response can be malformed, oversized, unexpected in type or malicious if the supplier is compromised. Validating what comes back is the same discipline as validating what comes in, and it is applied far less often because the source feels like a partner rather than a stranger.
Checked against the primary source.
