Unbounded Output
- Category
- Output Handling
- Confidence
- 60% confidence
- Finding
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
- Content
md - Pseudolocalization enabled in CI for at least one build that exercises the full UI - Expansion budget known (rule of thumb: short strings can grow 100–300%, German typically 30%, Russian 30–50%, Japanese can compress to 60%) - No fixed-width / fixed-height containers around translated text without overflow handling - No truncation that hides essential meaning (especially for verbs, prices, error messages) - Text-baseline alignment respects taller scripts (Devanagari, Thai, Arabic) — line-height not pinned to Latin x-height - Font stack covers target scripts (CJK, Arabic, Cyrillic, Devanagari, Thai, …) and fallbacks tested - Variable fonts / web-font subsets serve the right script
