diff --git a/src/main/java/org/eu/autogex/core/AbstractAutomatonBuilder.java b/src/main/java/org/eu/autogex/core/AbstractAutomatonBuilder.java index baa8c4d6..ea34a502 100644 --- a/src/main/java/org/eu/autogex/core/AbstractAutomatonBuilder.java +++ b/src/main/java/org/eu/autogex/core/AbstractAutomatonBuilder.java @@ -13,6 +13,9 @@ public abstract class AbstractAutomatonBuilder< B extends AbstractAutomatonBuilder, A extends Automaton> { + /** Maximum allowed states to prevent State Explosion (DoS) during manual construction */ + protected static final int MAX_STATES = 10000; + protected final Map states = new HashMap<>(); protected final Set finalStates = new HashSet<>(); protected State initialState; @@ -37,8 +40,15 @@ protected AbstractAutomatonBuilder() { * @param name The name of the state. * @param isFinal True if the state is an accepting state. * @return The current builder instance. + * @throws IllegalStateException if adding the state would exceed MAX_STATES. */ public B addState(String name, boolean isFinal) { + if (states.size() >= MAX_STATES && !states.containsKey(name)) { + throw new IllegalStateException( + "Exceeded maximum allowed states of " + + MAX_STATES + + " (Security: DoS prevention)."); + } State state = new State(name, isFinal); states.put(name, state); if (isFinal) {