There is no check on the limit of the number of token_ids that can be processed in one call.
The erc721_metadata
does not have a limit to look at the total token ids that can be processed at once. The creative attacker can design a situation where they place very many ids to be processed at once thus causing a griefing attack or a DOS. This can affect other innocent users' ability to use the same resources, especially DOS on protocol.
DOS attack on protocol
Manual review
Limit the amount of token_ids that can be processed within one single call in the erc721_metadata
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.