Open Access iconOpen Access

REVIEW

crossmark

Towards Secure APIs: A Survey on RESTful API Vulnerability Detection

Fatima Tanveer1, Faisal Iradat1,*, Waseem Iqbal2,*, Awais Ahmad3

1 Department of Computer Science, School of Mathematics and Science, Institute of Business Administration, Karachi, 75270, Pakistan
2 Department of Electrical and Computer Engineering, Sultan Qaboos University, Al-Khud, Muscat, 123, Oman
3 College of Computer and Information Sciences, Imam Mohammad Ibn Saud Islamic University (IMSIU), Riyadh, 11432, Saudi Arabia

* Corresponding Authors: Faisal Iradat. Email: email; Waseem Iqbal. Email: email

Computers, Materials & Continua 2025, 84(3), 4223-4257. https://doi.org/10.32604/cmc.2025.067536

Abstract

RESTful APIs have been adopted as the standard way of developing web services, allowing for smooth communication between clients and servers. Their simplicity, scalability, and compatibility have made them crucial to modern web environments. However, the increased adoption of RESTful APIs has simultaneously exposed these interfaces to significant security threats that jeopardize the availability, confidentiality, and integrity of web services. This survey focuses exclusively on RESTful APIs, providing an in-depth perspective distinct from studies addressing other API types such as GraphQL or SOAP. We highlight concrete threats—such as injection attacks and insecure direct object references (IDOR)—to illustrate the evolving risk landscape. Our work systematically reviews state-of-the-art detection methods, including static code analysis and penetration testing, and proposes a novel taxonomy that categorizes vulnerabilities such as authentication and authorization issues. Unlike existing taxonomies focused on general web or network-level threats, our taxonomy emphasizes API-specific design flaws and operational dependencies, offering a more granular and actionable framework for RESTful API security. By critically assessing current detection methodologies and identifying key research gaps, we offer a structured framework that advances the understanding and mitigation of RESTful API vulnerabilities. Ultimately, this work aims to drive significant advancements in API security, thereby enhancing the resilience of web services against evolving cyber threats.

Keywords

RESTful API; vulnerability detection; API security; taxonomy; systematic review

Cite This Article

APA Style
Tanveer, F., Iradat, F., Iqbal, W., Ahmad, A. (2025). Towards Secure APIs: A Survey on RESTful API Vulnerability Detection. Computers, Materials & Continua, 84(3), 4223–4257. https://doi.org/10.32604/cmc.2025.067536
Vancouver Style
Tanveer F, Iradat F, Iqbal W, Ahmad A. Towards Secure APIs: A Survey on RESTful API Vulnerability Detection. Comput Mater Contin. 2025;84(3):4223–4257. https://doi.org/10.32604/cmc.2025.067536
IEEE Style
F. Tanveer, F. Iradat, W. Iqbal, and A. Ahmad, “Towards Secure APIs: A Survey on RESTful API Vulnerability Detection,” Comput. Mater. Contin., vol. 84, no. 3, pp. 4223–4257, 2025. https://doi.org/10.32604/cmc.2025.067536



cc Copyright © 2025 The Author(s). Published by Tech Science Press.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
  • 2438

    View

  • 1051

    Download

  • 0

    Like

Share Link