SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-190 Integer Overflow or Wraparound

Coverage: 6 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 5Other-pattern 1 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow flagged integer math that can overflow/wrap and break safety checks (sizes, indices, limits). This is most critical in low-level languages, but can also matter in application code when values cross trust boundaries.

Why it matters

Overflows can bypass bounds checks or cause unexpected behavior.

Safer examples

1) Validate ranges and reject unexpected values

Validate sizes and counts at trust boundaries (see CWE-20 / CWE-400).

2) Use safe integer APIs where available

In languages with safe integer helpers (checked arithmetic), use them for sizes and indices.

3) Prefer languages/runtimes with built-in overflow safety

Even then, validate the maximums you will accept before allocating or looping.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.