undf: assign UNDF-2026-000001125 to mercurial-0001, stamp patches

This commit is contained in:
russell@unturf.com 2026-04-03 11:04:23 -04:00
parent 8b9d8d118b
commit 93c9c175d4
141 changed files with 935 additions and 5 deletions

View file

@ -1054,5 +1054,132 @@
"ryujinx-0001-0001": "UNDF-2026-000001053",
"sameboy-0001-0001": "UNDF-2026-000001054",
"sameboy-0002-0002": "UNDF-2026-000001055",
"vice-0001-0001": "UNDF-2026-000001056"
"vice-0001-0001": "UNDF-2026-000001056",
"aranym-0001-0001": "UNDF-2026-000001057",
"ardour-0001": "UNDF-2026-000001058",
"aria2-0001-0001": "UNDF-2026-000001059",
"audacity-2026": "UNDF-2026-000001060",
"azahar-0001-0001": "UNDF-2026-000001061",
"bind9-0001-0001": "UNDF-2026-000001062",
"blender-0004": "UNDF-2026-000001063",
"calligra-0001-0001": "UNDF-2026-000001064",
"caprice32-0001-0001": "UNDF-2026-000001065",
"caprice32-0002-0002": "UNDF-2026-000001066",
"citra-0001-0001": "UNDF-2026-000001067",
"cmake-0005-0005": "UNDF-2026-000001068",
"cmake-0006-0006": "UNDF-2026-000001069",
"cmake-0007-0007": "UNDF-2026-000001070",
"contiki-0001-0001": "UNDF-2026-000001071",
"cura-0001-0001": "UNDF-2026-000001072",
"curaengine-0001-0001": "UNDF-2026-000001073",
"cxbx-reloaded-0001-0001": "UNDF-2026-000001074",
"darktable-0004": "UNDF-2026-000001075",
"darktable-0005": "UNDF-2026-000001076",
"decaf-0001-0001": "UNDF-2026-000001077",
"desmume-0001-0001": "UNDF-2026-000001078",
"digikam-0003": "UNDF-2026-000001079",
"digikam-0004": "UNDF-2026-000001080",
"dnsmasq-0001-0001": "UNDF-2026-000001081",
"dolibarr-0004": "UNDF-2026-000001082",
"dolibarr-0005": "UNDF-2026-000001083",
"dosbox-x-0003-0003": "UNDF-2026-000001084",
"dosbox-x-0004-0004": "UNDF-2026-000001085",
"drone-0001-0001": "UNDF-2026-000001086",
"drone-0002-0002": "UNDF-2026-000001087",
"esp-idf-0001-0001": "UNDF-2026-000001088",
"esp-idf-0002-0002": "UNDF-2026-000001089",
"evolution-0001-0001": "UNDF-2026-000001090",
"ffmpeg-0004": "UNDF-2026-000001091",
"forgejo-0002-0002": "UNDF-2026-000001092",
"forgejo-0003-0003": "UNDF-2026-000001093",
"freecad-0003-0003": "UNDF-2026-000001094",
"freecad-0004-0004": "UNDF-2026-000001095",
"gearboy-0001-0001": "UNDF-2026-000001096",
"gearsystem-0001-0001": "UNDF-2026-000001097",
"gimp-0003": "UNDF-2026-000001098",
"gstreamer-0004": "UNDF-2026-000001099",
"gstreamer-0005": "UNDF-2026-000001100",
"inkscape-0004": "UNDF-2026-000001101",
"invoiceninja-0001-0001": "UNDF-2026-000001102",
"invoiceninja-0002-0002": "UNDF-2026-000001103",
"invoiceninja-0003-0003": "UNDF-2026-000001104",
"irssi-0001-0001": "UNDF-2026-000001105",
"jitsi-meet-0001-0001": "UNDF-2026-000001106",
"jitsi-meet-0002-0002": "UNDF-2026-000001107",
"jitsi-meet-0003-0003": "UNDF-2026-000001108",
"jitsi-meet-0004-0004": "UNDF-2026-000001109",
"julia-0003": "UNDF-2026-000001110",
"kdenlive-0009": "UNDF-2026-000001111",
"kdenlive-2026": "UNDF-2026-000001112",
"kicad-0003-0003": "UNDF-2026-000001113",
"kronos-0001-0001": "UNDF-2026-000001114",
"kronos-0002-0002": "UNDF-2026-000001115",
"langchain-0001-0001": "UNDF-2026-000001116",
"libjpeg-turbo-0001-0001": "UNDF-2026-000001117",
"libopenshot-0001-0001": "UNDF-2026-000001118",
"libreoffice-0001-0001": "UNDF-2026-000001119",
"libtiff-0001-0001": "UNDF-2026-000001120",
"lime3ds-0001-0001": "UNDF-2026-000001121",
"linapple-0001-0001": "UNDF-2026-000001122",
"llamacpp-0001-0001": "UNDF-2026-000001123",
"melonds-0001-0001": "UNDF-2026-000001124",
"mercurial-0001-0001": "UNDF-2026-000001125",
"mgba-0001-0001": "UNDF-2026-000001126",
"musescore-0001-0001": "UNDF-2026-000001127",
"musescore-0002-0002": "UNDF-2026-000001128",
"natron-0001": "UNDF-2026-000001129",
"ollama-0001-0001": "UNDF-2026-000001130",
"onlyoffice-0001-0001": "UNDF-2026-000001131",
"opencv-0003": "UNDF-2026-000001132",
"openemu-0001-0001": "UNDF-2026-000001133",
"openfoam-0002-0002": "UNDF-2026-000001134",
"openmsx-0001-0001": "UNDF-2026-000001135",
"openoffice-0001-0001": "UNDF-2026-000001136",
"openoffice-0002-0002": "UNDF-2026-000001137",
"openshot-0001-0001": "UNDF-2026-000001138",
"opentoonz-0001-0001": "UNDF-2026-000001139",
"pgbouncer-0001-0001": "UNDF-2026-000001140",
"pidgin-0001-0001": "UNDF-2026-000001141",
"pidgin-0002-0002": "UNDF-2026-000001142",
"pitivi-0001-0001": "UNDF-2026-000001143",
"play-0001-0001": "UNDF-2026-000001144",
"ppsspp-0004": "UNDF-2026-000001145",
"r-lang-0001-0001": "UNDF-2026-000001146",
"rawtherapee-0001-0001": "UNDF-2026-000001147",
"redmine-0004-0004": "UNDF-2026-000001148",
"retroarch-0002-0002": "UNDF-2026-000001149",
"rocketchat-0003": "UNDF-2026-000001150",
"rocketchat-0004": "UNDF-2026-000001151",
"root-cern-0001-0001": "UNDF-2026-000001152",
"root-cern-0002-0002": "UNDF-2026-000001153",
"rpcs3-0004": "UNDF-2026-000001154",
"ruffle-0001-0001": "UNDF-2026-000001155",
"ruffle-0002-0002": "UNDF-2026-000001156",
"scummvm-0001-0001": "UNDF-2026-000001157",
"scummvm-0002-0002": "UNDF-2026-000001158",
"snort3-0002-0002": "UNDF-2026-000001159",
"solvespace-0001-0001": "UNDF-2026-000001160",
"solvespace-0002-0002": "UNDF-2026-000001161",
"squid-0002-0002": "UNDF-2026-000001162",
"squid-0003-0003": "UNDF-2026-000001163",
"suitecrm-0004": "UNDF-2026-000001164",
"synfig-0001-0001": "UNDF-2026-000001165",
"systemd-0003": "UNDF-2026-000001166",
"taiga-0001-0001": "UNDF-2026-000001167",
"thunderbird-0007-0007": "UNDF-2026-000001168",
"thunderbird-0008-0008": "UNDF-2026-000001169",
"transformers-0002-0002": "UNDF-2026-000001170",
"transformers-0003-0003": "UNDF-2026-000001171",
"unbound-0001-0001": "UNDF-2026-000001172",
"vita3k-0001-0001": "UNDF-2026-000001173",
"vlc-0003-0003": "UNDF-2026-000001174",
"vllm-0002-0002": "UNDF-2026-000001175",
"wekan-0003-0003": "UNDF-2026-000001176",
"woodpecker-0001-0001": "UNDF-2026-000001177",
"woodpecker-0002-0001": "UNDF-2026-000001178",
"xenia-0001-0001": "UNDF-2026-000001179",
"yabause-0001-0001": "UNDF-2026-000001180",
"zephyr-0001-0001": "UNDF-2026-000001181",
"zephyr-0002-0002": "UNDF-2026-000001182",
"zesarux-0001-0001": "UNDF-2026-000001183"
}

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001057
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/hardware.cpp
+++ b/src/hardware.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001058
# UNDF: (leave blank)
# CWE-407: Algorithmic Complexity — PluginManager blacklist/rescan O(I * N)
# File: libs/ardour/plugin_manager.cc

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001059
# CWE-407: aria2 DHTPeerAnnounceEntry::addPeerAddrEntry peerAddrEntries_ O(P^2) scan
#
# DHTPeerAnnounceEntry tracks the set of peers that have announced themselves for a given

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001060
# Audacity — Full 5-MOAD Scan 2026-03-31
Source: https://github.com/audacity/audacity (depth=1, HEAD ~2026-03)

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001061
--- a/src/core/hle/service/am/am.cpp
+++ b/src/core/hle/service/am/am.cpp
@@ -1,6 +1,7 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001062
# UNDF:
--- a/lib/dns/zone.c
+++ b/lib/dns/zone.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001063
# UNDF: (leave blank)
# CWE-407: anim_channels_edit.cc rearrange_animchannel_islands BLI_findptr O(C*V)
#

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001064
--- a/libs/flake/KoShapeManager_p.h
+++ b/libs/flake/KoShapeManager_p.h
@@ -98,8 +98,10 @@ public:

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001065
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/z80.cpp
+++ b/src/z80.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001066
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/z80.cpp
+++ b/src/z80.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001067
--- a/src/video_core/rasterizer_cache/rasterizer_cache_base.h
+++ b/src/video_core/rasterizer_cache/rasterizer_cache_base.h
@@ -5,6 +5,7 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001068
# UNDF:
--- a/Source/cmQtAutoGen.cxx
+++ b/Source/cmQtAutoGen.cxx

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001069
# UNDF:
--- a/Source/cmVisualStudio10TargetGenerator.cxx
+++ b/Source/cmVisualStudio10TargetGenerator.cxx

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001070
# UNDF:
--- a/Source/cmGeneratorExpressionNode.cxx
+++ b/Source/cmGeneratorExpressionNode.cxx

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001071
--- a/os/services/lwm2m/lwm2m-security.c
+++ b/os/services/lwm2m/lwm2m-security.c
@@ -204,10 +204,8 @@ write_security_object(lwm2m_object_instance_t *object,

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001072
# UNDF: (leave blank — assigned later)
--- a/cura/Machines/Models/CompatibleMachineModel.py
+++ b/cura/Machines/Models/CompatibleMachineModel.py

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001073
# UNDF: (leave blank — assigned later)
--- a/src/PathOrderMonotonic.cpp
+++ b/src/PathOrderMonotonic.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001074
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/core/kernel/support/PatchRdtsc.cpp
+++ b/src/core/kernel/support/PatchRdtsc.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001075
# UNDF: (leave blank)
# CWE-312: darktable pwstorage backends log credentials verbatim when -d pwstorage
#

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001076
# UNDF: (leave blank)
# CWE-407: modulegroups.c _lib_modulegroups_test_visible O(M*G*P) per module visibility check
#

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001077
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/libdecaf/src/ios/mcp/ios_mcp_mcp_device.cpp
+++ b/src/libdecaf/src/ios/mcp/ios_mcp_mcp_device.cpp

View file

@ -1,4 +1,4 @@
# UNDF: UNDF-2026-000001058
# UNDF: UNDF-2026-000001078
--- a/desmume/src/NDSSystem.cpp
+++ b/desmume/src/NDSSystem.cpp
@@ -1,5 +1,6 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001079
# UNDF: (leave blank)
# CWE-407: Algorithmic Complexity — XMP keyword bag merge QStringList::contains() in loop
# Severity: MEDIUM

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001080
# UNDF: (leave blank)
# CWE-312: Cleartext Storage of Sensitive Information — OAuth2 client secret logged verbatim
# Severity: HIGH

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001081
# dnsmasq 5-MOAD scan — 2026-03-31
Source: https://thekelleys.org.uk/git/dnsmasq.git (depth=1)

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001081
# dnsmasq-0001: option_filter() duplicate elimination O(N²) — CWE-407
## Severity

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001082
--- a/htdocs/admin/emailcollector_card.php
+++ b/htdocs/admin/emailcollector_card.php
@@ -572,7 +572,7 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001083
--- a/htdocs/core/login/functions_ldap.php
+++ b/htdocs/core/login/functions_ldap.php
@@ -95,9 +95,9 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001084
--- a/src/hardware/vga_draw.cpp
+++ b/src/hardware/vga_draw.cpp
@@ -2585 +2585 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001085
--- a/src/dos/drive_local.cpp
+++ b/src/dos/drive_local.cpp
@@ -278 +278 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001086
--- a/pubsub/inmem.go
+++ b/pubsub/inmem.go
@@ -14,7 +14,6 @@ import (

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001087
--- a/cache/ttl_cache.go
+++ b/cache/ttl_cache.go
@@ -14,6 +14,7 @@ import (

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001088
--- a/components/esp_wifi/src/smartconfig.c
+++ b/components/esp_wifi/src/smartconfig.c
@@ -32,7 +32,6 @@ static void handler_got_ssid_passwd(void *arg, esp_event_base_t base, int32_t e

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001089
--- a/components/esp_http_client/lib/http_auth.c
+++ b/components/esp_http_client/lib/http_auth.c
@@ -155,7 +155,6 @@ char *http_auth_digest(const char *username, const char *password, esp_http_auth

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001090
# UNDF:
--- a/src/calendar/gui/e-date-time-list.c
+++ b/src/calendar/gui/e-date-time-list.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001091
# UNDF: (pending)
# CWE-312: Cleartext Storage of Sensitive Information — HTTP Authorization header logged at AV_LOG_DEBUG
# File: libavformat/http.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000684
# FFmpeg — MOAD-0002 through MOAD-0005 scan
## Scope

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001092
--- a/modules/repository/init.go
+++ b/modules/repository/init.go
@@ -104,13 +104,16 @@ func LoadRepoConfig() error {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001093
--- a/models/asymkey/ssh_key.go
+++ b/models/asymkey/ssh_key.go
@@ -378,19 +378,22 @@ func synchronizePublicKeys(ctx context.Context, s *auth.Source, usr *user_model.

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001094
# UNDF: (leave blank — assigned later)
# FreeCAD freecad-0003: CrossSection::removeDuplicates O(W^2 * E) wire dedup
#

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001095
# UNDF: (leave blank — assigned later)
# FreeCAD freecad-0004: SketchAnalysis::detectMissingEqualityConstraints O(C * E_eq)
#

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001096
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/Processor.h
+++ b/src/Processor.h

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001097
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/Processor.h
+++ b/src/Processor.h

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001098
# UNDF: (leave blank)
# CWE-407: Algorithmic Complexity — xcf_save_layer_props layer_sets O(L × S × I)
# File: app/xcf/xcf-save.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001099
--- a/subprojects/gst-plugins-good/gst/rtsp/gstrtspsrc.c
+++ b/subprojects/gst-plugins-good/gst/rtsp/gstrtspsrc.c
@@ -1998,8 +1998,12 @@ gst_rtspsrc_set_proxy (GstRTSPSrc * rtsp, const gchar * proxy)

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001100
--- a/subprojects/gst-plugins-bad/ext/webrtc/gstwebrtcbin.c
+++ b/subprojects/gst-plugins-bad/ext/webrtc/gstwebrtcbin.c
@@ -3964,7 +3964,13 @@ _create_offer_task (GstWebRTCBin * webrtc, const GstStructure * options,

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001101
# UNDF: (leave blank)
# CWE-407: Algorithmic Complexity — LayerManager::_rebuild() std::find O(L² × D)
# File: src/layer-manager.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001102
--- a/app/Console/Commands/S3Cleanup.php
+++ b/app/Console/Commands/S3Cleanup.php
@@ -55,17 +55,19 @@ class S3Cleanup extends Command

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001103
--- a/app/PaymentDrivers/CheckoutComPaymentDriver.php
+++ b/app/PaymentDrivers/CheckoutComPaymentDriver.php
@@ -570,11 +570,12 @@ class CheckoutComPaymentDriver extends BaseDriver

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001104
--- a/app/Mail/DownloadReport.php
+++ b/app/Mail/DownloadReport.php
@@ -37,6 +37,7 @@ class DownloadReport extends Mailable

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001105
# UNDF: (assigned later)
# Target: irssi
# MOAD: 0004 — CWE-312 Cleartext Storage of Sensitive Information

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001105
# UNDF: (assigned later)
--- a/src/core/rawlog.c
+++ b/src/core/rawlog.c

View file

@ -0,0 +1,44 @@
# jitsi-meet-0001 — MOAD-0001 CWE-407
## Location
`react/features/connection-stats/components/ConnectionStatsTable.tsx`
Function `_renderTransport()`, line 452
## Pattern
O(T²): a `for` loop over `transport[]` (ICE candidate pairs) performs 5 independent
`.includes()` calls on 5 growing arrays (`remoteIP`, `localIP`, `localPort`,
`remotePort`, `transportType`) per iteration. Each `.includes()` is O(T), so our
inner body is O(5T) and our full loop is O(5T²).
```typescript
for (let i = 0; i < transport.length; i++) {
if (!data.remoteIP.includes(ip)) { data.remoteIP.push(ip); }
if (!data.localIP.includes(localIP)) { data.localIP.push(localIP); }
if (!data.localPort.includes(localPort)) { data.localPort.push(localPort); }
if (!data.remotePort.includes(port)) { data.remotePort.push(port); }
if (!data.transportType.includes(transport[i].type)) { ... }
}
```
## Severity
MEDIUM. WebRTC `RTCIceCandidatePairStats` reports one entry per ICE candidate
pair. A host with many network interfaces (corporate VPN + WiFi + Ethernet + loopback)
can produce 20-50 pairs. At T=50: 5×50×50 = 12,500 comparisons vs 5×50 = 250
with Sets. 50x overhead.
## Fix
Introduce 5 `Set<string>` instances outside our loop. Replace `.includes()` with
`.has()` (O(1)) and `.add()` on membership miss. Arrays are still built for output;
Sets shadow them for membership testing only.
## All 5 MOADs
- MOAD-0001: CONFIRMED (this defect)
- MOAD-0002: CLEAN (Redux architecture is intentional; APP global is a thin facade)
- MOAD-0003: CLEAN (no AsyncLocalStorage misuse found)
- MOAD-0004: CLEAN (no JWT/token values appear in log statements)
- MOAD-0005: CLEAN (JavaScript is single-threaded; no async cache races)

View file

@ -0,0 +1,58 @@
# UNDF: UNDF-2026-000001106
# UNDF:
--- a/react/features/connection-stats/components/ConnectionStatsTable.tsx
+++ b/react/features/connection-stats/components/ConnectionStatsTable.tsx
@@ -438,29 +438,29 @@ const ConnectionStatsTable = ({
localPort: string[];
remoteIP: string[];
remotePort: string[];
transportType: string[];
} = {
localIP: [],
localPort: [],
remoteIP: [],
remotePort: [],
transportType: []
};
+ const seenRemoteIP = new Set<string>();
+ const seenLocalIP = new Set<string>();
+ const seenLocalPort = new Set<string>();
+ const seenRemotePort = new Set<string>();
+ const seenTransportType = new Set<string>();
for (let i = 0; i < transport.length; i++) {
const ip = getIP(transport[i].ip);
const localIP = getIP(transport[i].localip);
const localPort = getPort(transport[i].localip);
const port = getPort(transport[i].ip);
- if (!data.remoteIP.includes(ip)) {
+ if (!seenRemoteIP.has(ip)) {
+ seenRemoteIP.add(ip);
data.remoteIP.push(ip);
}
- if (!data.localIP.includes(localIP)) {
+ if (!seenLocalIP.has(localIP)) {
+ seenLocalIP.add(localIP);
data.localIP.push(localIP);
}
- if (!data.localPort.includes(localPort)) {
+ if (!seenLocalPort.has(localPort)) {
+ seenLocalPort.add(localPort);
data.localPort.push(localPort);
}
- if (!data.remotePort.includes(port)) {
+ if (!seenRemotePort.has(port)) {
+ seenRemotePort.add(port);
data.remotePort.push(port);
}
- if (!data.transportType.includes(transport[i].type)) {
+ if (!seenTransportType.has(transport[i].type)) {
+ seenTransportType.add(transport[i].type);
data.transportType.push(transport[i].type);
}
}

View file

@ -0,0 +1,145 @@
package unit;
import java.util.*;
/**
* Models jitsi-meet ConnectionStatsTable._renderTransport() dedup pattern.
*
* Defect: 5x array.includes() O(T) inside for-loop over T transport entries O(T²).
* Fix: 5x Set.has() O(1) for membership O(T).
*
* jitsi-meet-0001 MOAD-0001 CWE-407
* No JUnit compile and run standalone.
*/
public class JitsiMeetTransportDedupTest {
record Transport(String remoteIP, String localIP, String localPort,
String remotePort, String transportType) {}
// -------------------------------------------------------------------
// DEFECT: O(T²) List.contains() inside loop, 5 checks per entry
// -------------------------------------------------------------------
static long slowDedup(List<Transport> transports) {
List<String> remoteIP = new ArrayList<>();
List<String> localIP = new ArrayList<>();
List<String> localPort = new ArrayList<>();
List<String> remotePort = new ArrayList<>();
List<String> transportType = new ArrayList<>();
long ops = 0;
for (Transport t : transports) {
ops += remoteIP.size();
if (!remoteIP.contains(t.remoteIP())) remoteIP.add(t.remoteIP());
ops += localIP.size();
if (!localIP.contains(t.localIP())) localIP.add(t.localIP());
ops += localPort.size();
if (!localPort.contains(t.localPort())) localPort.add(t.localPort());
ops += remotePort.size();
if (!remotePort.contains(t.remotePort())) remotePort.add(t.remotePort());
ops += transportType.size();
if (!transportType.contains(t.transportType())) transportType.add(t.transportType());
}
return ops;
}
// -------------------------------------------------------------------
// FIX: O(T) Set.contains() O(1), arrays still built for output
// -------------------------------------------------------------------
static long fastDedup(List<Transport> transports) {
List<String> remoteIP = new ArrayList<>();
List<String> localIP = new ArrayList<>();
List<String> localPort = new ArrayList<>();
List<String> remotePort = new ArrayList<>();
List<String> transportType = new ArrayList<>();
Set<String> seenRemoteIP = new HashSet<>();
Set<String> seenLocalIP = new HashSet<>();
Set<String> seenLocalPort = new HashSet<>();
Set<String> seenRemotePort = new HashSet<>();
Set<String> seenTransportType = new HashSet<>();
long ops = 0;
for (Transport t : transports) {
ops++;
if (seenRemoteIP.add(t.remoteIP())) remoteIP.add(t.remoteIP());
ops++;
if (seenLocalIP.add(t.localIP())) localIP.add(t.localIP());
ops++;
if (seenLocalPort.add(t.localPort())) localPort.add(t.localPort());
ops++;
if (seenRemotePort.add(t.remotePort())) remotePort.add(t.remotePort());
ops++;
if (seenTransportType.add(t.transportType())) transportType.add(t.transportType());
}
return ops;
}
static List<Transport> makeTransports(int n) {
List<Transport> list = new ArrayList<>();
for (int i = 0; i < n; i++) {
list.add(new Transport(
"10.0." + (i / 256) + "." + (i % 256),
"192.168." + (i / 256) + "." + (i % 256),
String.valueOf(5000 + i),
String.valueOf(4000 + i),
i % 2 == 0 ? "udp" : "tcp"
));
}
return list;
}
static List<Transport> makeDuplicateTransports(int n) {
List<Transport> list = new ArrayList<>();
for (int i = 0; i < n; i++) {
// All entries share same fields maximum dedup pressure
list.add(new Transport("10.0.0.1", "192.168.1.1", "5000", "4000", "udp"));
}
return list;
}
public static void main(String[] args) {
int tests = 0, passed = 0;
// --- correctness: unique transports ---
tests++;
{
List<Transport> inputs = makeTransports(10);
// Both should produce same unique set sizes
long slowOps = slowDedup(inputs);
long fastOps = fastDedup(inputs);
// Slow must have done more work than fast
boolean ok = slowOps >= fastOps;
System.out.printf("%s correctness-unique T=10 slowOps=%d fastOps=%d%n",
ok ? "PASS" : "FAIL", slowOps, fastOps);
if (ok) passed++;
}
// --- correctness: duplicate transports ---
tests++;
{
List<Transport> inputs = makeDuplicateTransports(20);
long slowOps = slowDedup(inputs);
long fastOps = fastDedup(inputs);
boolean ok = slowOps > fastOps;
System.out.printf("%s correctness-dups T=20 slowOps=%d fastOps=%d%n",
ok ? "PASS" : "FAIL", slowOps, fastOps);
if (ok) passed++;
}
// --- speedup benchmarks ---
int[] benchSizes = {20, 50, 100, 200};
for (int n : benchSizes) {
tests++;
List<Transport> inputs = makeTransports(n);
// Op counts as proxy for algorithmic complexity ratio
long slowOps = slowDedup(inputs);
long fastOps = fastDedup(inputs);
double ratio = (double) slowOps / fastOps;
// At T=50 unique entries: slow = 5 * sum(0..49) = 5*1225 = 6125; fast = 5*50 = 250 24.5x
boolean ok = ratio >= 2.0;
System.out.printf("%s speedup T=%d slowOps=%d fastOps=%d ratio=%.1fx%n",
ok ? "PASS" : "FAIL", n, slowOps, fastOps, ratio);
if (ok) passed++;
}
System.out.println("\n" + passed + "/" + tests + " PASS");
if (passed != tests) System.exit(1);
}
}

View file

@ -0,0 +1,43 @@
# jitsi-meet-0002 — MOAD-0001 CWE-407
## Location
`react/features/chat/components/web/MessageContainer.tsx`
`componentDidUpdate()`, line 179
## Pattern
O(M²): on every React update cycle after a new chat message arrives,
`this.props.messages.filter(message => !prevProps.messages.includes(message))`
scans our full previous message array for each current message. With M messages,
our `.filter` iterates M entries and each `.includes()` walks up to M entries of
`prevProps.messages`.
```typescript
const newMessages = this.props.messages.filter(
message => !prevProps.messages.includes(message) // O(M) per entry
);
const hasLocalMessage = newMessages.map(message => message.messageType)
.includes(MESSAGE_TYPE_LOCAL); // O(M) second scan
```
Our secondary scan also maps then includes — two passes when `.some()` suffices.
## Severity
MEDIUM. Jitsi chat rooms in large conferences can accumulate hundreds of messages
over a meeting. Each incoming message triggers `componentDidUpdate`, scanning
all prior messages. At M=500: 500×500 = 250,000 comparisons vs 500 with Set.
500x overhead on our hottest render path.
## Fix
Build a `Set` from `prevProps.messages` once before our filter. Replace `.includes()`
with `.has()` (O(1)). Replace `.map().includes()` with `.some()` — eliminates our
intermediate array allocation and second O(M) scan.
## Similar pattern (native)
`react/features/chat/components/native/SubtitlesMessagesContainer.tsx` line 138
uses identical pattern: `messages.filter(message => !previousMessages.current.includes(message))`.
Same fix applies.

View file

@ -0,0 +1,16 @@
# UNDF: UNDF-2026-000001107
# UNDF:
--- a/react/features/chat/components/web/MessageContainer.tsx
+++ b/react/features/chat/components/web/MessageContainer.tsx
@@ -176,8 +176,9 @@ class MessageContainer extends Component<IProps, IState> {
* @returns {void}
*/
override componentDidUpdate(prevProps: IProps) {
- const newMessages = this.props.messages.filter(message => !prevProps.messages.includes(message));
- const hasLocalMessage = newMessages.map(message => message.messageType).includes(MESSAGE_TYPE_LOCAL);
+ const prevSet = new Set(prevProps.messages);
+ const newMessages = this.props.messages.filter(message => !prevSet.has(message));
+ const hasLocalMessage = newMessages.some(message => message.messageType === MESSAGE_TYPE_LOCAL);
if (newMessages.length > 0) {
if (this.state.isScrolledToBottom || hasLocalMessage) {

View file

@ -0,0 +1,120 @@
package unit;
import java.util.*;
import java.util.stream.*;
/**
* Models jitsi-meet MessageContainer.componentDidUpdate() new-message detection.
*
* Defect: messages.filter(m => !prevMessages.includes(m)) O(M²) on every update.
* then .map().includes() O(M) second scan that .some() replaces in O(M).
* Fix: build Set from prevMessages once, use Set.contains() O(M) total.
* use stream().anyMatch() instead of .map().contains().
*
* jitsi-meet-0002 MOAD-0001 CWE-407
* No JUnit compile and run standalone.
*/
public class JitsiMeetMessageDedupTest {
static final String LOCAL = "local";
static final String REMOTE = "remote";
record Message(int id, String messageType) {}
// -------------------------------------------------------------------
// DEFECT: O(M²) List.contains() inside filter per message
// -------------------------------------------------------------------
static long slowFindNew(List<Message> messages, List<Message> prevMessages) {
long ops = 0;
List<Message> newMessages = new ArrayList<>();
for (Message m : messages) {
ops += prevMessages.size(); // O(M) per entry
if (!prevMessages.contains(m)) newMessages.add(m);
}
// Secondary scan: .map().contains() another O(N)
List<String> types = new ArrayList<>();
for (Message m : newMessages) types.add(m.messageType());
ops += types.size();
boolean hasLocal = types.contains(LOCAL);
return ops;
}
// -------------------------------------------------------------------
// FIX: O(M) Set built once, anyMatch() replaces map+contains
// -------------------------------------------------------------------
static long fastFindNew(List<Message> messages, List<Message> prevMessages) {
long ops = 0;
Set<Message> prevSet = new HashSet<>(prevMessages);
List<Message> newMessages = new ArrayList<>();
for (Message m : messages) {
ops++; // O(1) Set.contains
if (!prevSet.contains(m)) newMessages.add(m);
}
ops++;
boolean hasLocal = newMessages.stream().anyMatch(m -> LOCAL.equals(m.messageType()));
return ops;
}
static List<Message> makeMessages(int n) {
List<Message> list = new ArrayList<>();
for (int i = 0; i < n; i++) {
list.add(new Message(i, i % 10 == 0 ? LOCAL : REMOTE));
}
return list;
}
public static void main(String[] args) {
int tests = 0, passed = 0;
// --- correctness: single new message ---
tests++;
{
List<Message> prev = makeMessages(50);
List<Message> cur = new ArrayList<>(prev);
Message newMsg = new Message(999, LOCAL);
cur.add(newMsg);
long slowOps = slowFindNew(cur, prev);
long fastOps = fastFindNew(cur, prev);
boolean ok = slowOps > fastOps;
System.out.printf("%s correctness-one-new slowOps=%d fastOps=%d%n",
ok ? "PASS" : "FAIL", slowOps, fastOps);
if (ok) passed++;
}
// --- correctness: no new messages ---
tests++;
{
List<Message> messages = makeMessages(30);
long slowOps = slowFindNew(messages, messages);
long fastOps = fastFindNew(messages, messages);
// Both find zero new messages; slow must do more work
boolean ok = slowOps > fastOps;
System.out.printf("%s correctness-no-new slowOps=%d fastOps=%d%n",
ok ? "PASS" : "FAIL", slowOps, fastOps);
if (ok) passed++;
}
// --- speedup benchmarks ---
int[] benchSizes = {50, 100, 250, 500};
for (int M : benchSizes) {
tests++;
List<Message> prev = makeMessages(M);
List<Message> cur = new ArrayList<>(prev);
cur.add(new Message(M + 1, LOCAL));
long slowOps = slowFindNew(cur, prev);
long fastOps = fastFindNew(cur, prev);
double ratio = (double) slowOps / fastOps;
// At M=500: slow = 500*500 = 250,000; fast = 501 ~499x
boolean ok = ratio >= 5.0;
System.out.printf("%s speedup M=%d slowOps=%d fastOps=%d ratio=%.1fx%n",
ok ? "PASS" : "FAIL", M, slowOps, fastOps, ratio);
if (ok) passed++;
}
System.out.println("\n" + passed + "/" + tests + " PASS");
if (passed != tests) System.exit(1);
}
}

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001108
# UNDF: (to be assigned)
--- a/react/features/av-moderation/reducer.ts
+++ b/react/features/av-moderation/reducer.ts

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001109
# UNDF: (to be assigned)
--- a/react/features/visitors/middleware.ts
+++ b/react/features/visitors/middleware.ts

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001110
# UNDF: (leave blank — assigned later)
## Classification

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001111
# UNDF: (leave blank)
# Defect: kdenlive-0009
# Component: src/core.cpp + src/mainwindow.h — buildLumaThumbs / m_lumacache

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001112
# Kdenlive — Full 5-MOAD Scan 2026-03-31
Source: https://github.com/KDE/kdenlive (depth=1, HEAD ~2026-03)

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001113
# UNDF: (leave blank — assigned later)
# KiCad kicad-0003: BOARD_NETLIST_UPDATER::testConnectivity FindPadByNumber O(N*P)
#

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001114
# UNDF: UNDF-2026-XXXXXXXXX
--- a/yabause/src/sys/sh2/include/sh2core.h
+++ b/yabause/src/sys/sh2/include/sh2core.h

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001115
# UNDF: UNDF-2026-XXXXXXXXX
--- a/yabause/src/utils/src/netlink.c
+++ b/yabause/src/utils/src/netlink.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001116
--- a/libs/langchain/langchain_classic/retrievers/multi_vector.py
+++ b/libs/langchain/langchain_classic/retrievers/multi_vector.py
@@ -105,9 +105,10 @@ class MultiVectorRetriever(BaseRetriever):

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001117
# UNDF: (leave blank — assigned later)
--- a/src/rdcolmap.c
+++ b/src/rdcolmap.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001118
# UNDF: (leave blank)
# CWE-407: Algorithmic Complexity (list membership inside per-frame loop)
# libopenshot ObjectDetection effect: display_classes filter uses std::find on a

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001119
--- a/sc/source/filter/excel/xepivotxml.cxx
+++ b/sc/source/filter/excel/xepivotxml.cxx
@@ -1404,16 +1404,22 @@ void XclExpXmlPivotTables::SavePivotTableXml( XclExpXmlStream& rStrm, const ScD

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001120
# UNDF:
--- a/libtiff/tif_dirread.c
+++ b/libtiff/tif_dirread.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001121
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/network/room.cpp
+++ b/src/network/room.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001122
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/Applewin.cpp
+++ b/src/Applewin.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001123
# CWE-407: llama.cpp llama_grammar_advance_stack / llama_grammar_accept_token
# new_stacks / stacks_new dedup via std::find on vector<vector<ptr>> — O(S^2) per token
#

View file

@ -1,4 +1,4 @@
# UNDF: UNDF-2026-000001057
# UNDF: UNDF-2026-000001124
--- a/src/GPU3D_Soft.cpp
+++ b/src/GPU3D_Soft.cpp
@@ -19,6 +19,7 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001125
diff -r 780af01abd69 mercurial/graphmod.py
--- a/mercurial/graphmod.py Wed Apr 01 19:48:46 2026 +0200
+++ b/mercurial/graphmod.py Fri Apr 03 11:03:45 2026 -0400

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001126
# UNDF:
--- a/src/sm83/debugger/debugger.c
+++ b/src/sm83/debugger/debugger.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001127
--- a/src/engraving/rw/read400/read400.cpp
+++ b/src/engraving/rw/read400/read400.cpp
@@ -331,7 +331,7 @@ bool Read400::pasteStaff(XmlReader& e, Segment* dst, staff_idx_t dstStaff, Frac

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001128
--- a/src/framework/cloud/internal/abstractcloudservice.cpp
+++ b/src/framework/cloud/internal/abstractcloudservice.cpp
@@ -215,7 +215,7 @@ void AbstractCloudService::onUserAuthorized()

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001129
# UNDF: (leave blank)
# CWE-407: Algorithmic Complexity — node graph traversal visited-set O(N^2)
# File: Engine/Node.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001130
--- a/kvcache/causal.go
+++ b/kvcache/causal.go
@@ -362,12 +362,17 @@ func (c *Causal) buildMask(ctx ml.Context) ml.Tensor {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001131
--- a/word/Editor/Table.js
+++ b/word/Editor/Table.js
@@ -12305,12 +12305,13 @@ CTable.prototype.SelectCells = function(X1, Y1, X2, Y2, CurPageStart, drawMode)

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001132
--- a/modules/dnn/src/onnx/onnx_importer.cpp
+++ b/modules/dnn/src/onnx/onnx_importer.cpp
@@ -724,38 +724,44 @@ std::string ONNXImporter::getLayerTypeDomain(const opencv_onnx::NodeProto& node_

View file

@ -1,4 +1,4 @@
# UNDF: UNDF-2026-000001058
# UNDF: UNDF-2026-000001133
# OpenEmu openemu-0001: SetupAssistant knownCores Array.contains O(N^2) in core dedup loop
#
# SetupAssistant.swift performs initial core list population on the transition

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001134
# UNDF:
--- a/src/finiteVolume/fvMesh/extendedStencil/faceToCell/globalIndexStencils/CFCFaceToCellStencil.C
+++ b/src/finiteVolume/fvMesh/extendedStencil/faceToCell/globalIndexStencils/CFCFaceToCellStencil.C

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001135
# UNDF: UNDF-2026-XXXXXXXXX
--- a/src/cpu/MSXCPUInterface.hh
+++ b/src/cpu/MSXCPUInterface.hh

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001136
# Apache OpenOffice — 5-MOAD Scan Result
Scanned: 2026-04-01

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001136
# openoffice-0001: XclExpXFBuffer::AddBorderAndFill O(N²) std::find_if on maBorders/maFills
#
# In main/sc/source/filter/excel/xestyle.cxx, AddBorderAndFill() is called once

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001137
# openoffice-0002: CurlSession::curlDebugOutput logs HTTP headers verbatim — MOAD-0004 (CWE-312)
#
# In main/ucb/source/ucp/webdav/CurlSession.cxx, when our WebDAV logger is

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001138
# UNDF: (leave blank)
# CWE-407: Algorithmic Complexity (linear scan inside loop over selected items)
# OpenShot-Qt query.py: QueryObject.filter() scans ALL objects of a type (O(N))

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001139
# UNDF: (leave blank)
# CWE-407: Algorithmic Complexity (list membership scan inside vectorization loop)
# OpenToonz autoclose.cpp: TAutocloser::Imp::spotResearchOnePoint calls

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001140
--- a/src/client.c
+++ b/src/client.c
@@ -1121,7 +1121,7 @@ static bool scram_client_first(PgSocket *client, uint32_t datalen, const uint8_t

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001141
# UNDF:
--- a/libpurple/privacy.c
+++ b/libpurple/privacy.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001142
# pidgin-0002: SIP SIMPLE Authorization header logged verbatim (CWE-312)
## MOAD

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001143
# UNDF: (leave blank — assigned later)
--- a/pitivi/medialibrary.py
+++ b/pitivi/medialibrary.py

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001144
--- a/Source/iop/IopBios.h
+++ b/Source/iop/IopBios.h
@@ -670,6 +670,7 @@ private:

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001145
--- a/Core/HLE/sceKernelMutex.cpp
+++ b/Core/HLE/sceKernelMutex.cpp
@@ -547,3 +547,3 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001146
# UNDF: (leave blank — assigned later)
--- a/src/library/base/R/namespace.R
+++ b/src/library/base/R/namespace.R

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000001147
# Defect: rawtherapee-0001
# Component: rtgui/batchqueue.cc — BatchQueue::cancelItems(), headItems(), tailItems()
# Pattern: CWE-407 — std::find(fd.begin(), fd.end(), entry) inside loop over items

Some files were not shown because too many files have changed in this diff Show more