NullX Finding 2: unbounded size param allowed full table scan. Added spring-boot-starter-validation, @Validated on the controller, @Min(1) @Max(100) on the size param, and ConstraintViolationException → 400 in GlobalExceptionHandler. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>