diff --git a/UNDF-REGISTRY.json b/UNDF-REGISTRY.json index 3b6b608ea..d48240fb1 100644 --- a/UNDF-REGISTRY.json +++ b/UNDF-REGISTRY.json @@ -1054,5 +1054,132 @@ "ryujinx-0001-0001": "UNDF-2026-000001053", "sameboy-0001-0001": "UNDF-2026-000001054", "sameboy-0002-0002": "UNDF-2026-000001055", - "vice-0001-0001": "UNDF-2026-000001056" + "vice-0001-0001": "UNDF-2026-000001056", + "aranym-0001-0001": "UNDF-2026-000001057", + "ardour-0001": "UNDF-2026-000001058", + "aria2-0001-0001": "UNDF-2026-000001059", + "audacity-2026": "UNDF-2026-000001060", + "azahar-0001-0001": "UNDF-2026-000001061", + "bind9-0001-0001": "UNDF-2026-000001062", + "blender-0004": "UNDF-2026-000001063", + "calligra-0001-0001": "UNDF-2026-000001064", + "caprice32-0001-0001": "UNDF-2026-000001065", + "caprice32-0002-0002": "UNDF-2026-000001066", + "citra-0001-0001": "UNDF-2026-000001067", + "cmake-0005-0005": "UNDF-2026-000001068", + "cmake-0006-0006": "UNDF-2026-000001069", + "cmake-0007-0007": "UNDF-2026-000001070", + "contiki-0001-0001": "UNDF-2026-000001071", + "cura-0001-0001": "UNDF-2026-000001072", + "curaengine-0001-0001": "UNDF-2026-000001073", + "cxbx-reloaded-0001-0001": "UNDF-2026-000001074", + "darktable-0004": "UNDF-2026-000001075", + "darktable-0005": "UNDF-2026-000001076", + "decaf-0001-0001": "UNDF-2026-000001077", + "desmume-0001-0001": "UNDF-2026-000001078", + "digikam-0003": "UNDF-2026-000001079", + "digikam-0004": "UNDF-2026-000001080", + "dnsmasq-0001-0001": "UNDF-2026-000001081", + "dolibarr-0004": "UNDF-2026-000001082", + "dolibarr-0005": "UNDF-2026-000001083", + "dosbox-x-0003-0003": "UNDF-2026-000001084", + "dosbox-x-0004-0004": "UNDF-2026-000001085", + "drone-0001-0001": "UNDF-2026-000001086", + "drone-0002-0002": "UNDF-2026-000001087", + "esp-idf-0001-0001": "UNDF-2026-000001088", + "esp-idf-0002-0002": "UNDF-2026-000001089", + "evolution-0001-0001": "UNDF-2026-000001090", + "ffmpeg-0004": "UNDF-2026-000001091", + "forgejo-0002-0002": "UNDF-2026-000001092", + "forgejo-0003-0003": "UNDF-2026-000001093", + "freecad-0003-0003": "UNDF-2026-000001094", + "freecad-0004-0004": "UNDF-2026-000001095", + "gearboy-0001-0001": "UNDF-2026-000001096", + "gearsystem-0001-0001": "UNDF-2026-000001097", + "gimp-0003": "UNDF-2026-000001098", + "gstreamer-0004": "UNDF-2026-000001099", + "gstreamer-0005": "UNDF-2026-000001100", + "inkscape-0004": "UNDF-2026-000001101", + "invoiceninja-0001-0001": "UNDF-2026-000001102", + "invoiceninja-0002-0002": "UNDF-2026-000001103", + "invoiceninja-0003-0003": "UNDF-2026-000001104", + "irssi-0001-0001": "UNDF-2026-000001105", + "jitsi-meet-0001-0001": "UNDF-2026-000001106", + "jitsi-meet-0002-0002": "UNDF-2026-000001107", + "jitsi-meet-0003-0003": "UNDF-2026-000001108", + "jitsi-meet-0004-0004": "UNDF-2026-000001109", + "julia-0003": "UNDF-2026-000001110", + "kdenlive-0009": "UNDF-2026-000001111", + "kdenlive-2026": "UNDF-2026-000001112", + "kicad-0003-0003": "UNDF-2026-000001113", + "kronos-0001-0001": "UNDF-2026-000001114", + "kronos-0002-0002": "UNDF-2026-000001115", + "langchain-0001-0001": "UNDF-2026-000001116", + "libjpeg-turbo-0001-0001": "UNDF-2026-000001117", + "libopenshot-0001-0001": "UNDF-2026-000001118", + "libreoffice-0001-0001": "UNDF-2026-000001119", + "libtiff-0001-0001": "UNDF-2026-000001120", + "lime3ds-0001-0001": "UNDF-2026-000001121", + "linapple-0001-0001": "UNDF-2026-000001122", + "llamacpp-0001-0001": "UNDF-2026-000001123", + "melonds-0001-0001": "UNDF-2026-000001124", + "mercurial-0001-0001": "UNDF-2026-000001125", + "mgba-0001-0001": "UNDF-2026-000001126", + "musescore-0001-0001": "UNDF-2026-000001127", + "musescore-0002-0002": "UNDF-2026-000001128", + "natron-0001": "UNDF-2026-000001129", + "ollama-0001-0001": "UNDF-2026-000001130", + "onlyoffice-0001-0001": "UNDF-2026-000001131", + "opencv-0003": "UNDF-2026-000001132", + "openemu-0001-0001": "UNDF-2026-000001133", + "openfoam-0002-0002": "UNDF-2026-000001134", + "openmsx-0001-0001": "UNDF-2026-000001135", + "openoffice-0001-0001": "UNDF-2026-000001136", + "openoffice-0002-0002": "UNDF-2026-000001137", + "openshot-0001-0001": "UNDF-2026-000001138", + "opentoonz-0001-0001": "UNDF-2026-000001139", + "pgbouncer-0001-0001": "UNDF-2026-000001140", + "pidgin-0001-0001": "UNDF-2026-000001141", + "pidgin-0002-0002": "UNDF-2026-000001142", + "pitivi-0001-0001": "UNDF-2026-000001143", + "play-0001-0001": "UNDF-2026-000001144", + "ppsspp-0004": "UNDF-2026-000001145", + "r-lang-0001-0001": "UNDF-2026-000001146", + "rawtherapee-0001-0001": "UNDF-2026-000001147", + "redmine-0004-0004": "UNDF-2026-000001148", + "retroarch-0002-0002": "UNDF-2026-000001149", + "rocketchat-0003": "UNDF-2026-000001150", + "rocketchat-0004": "UNDF-2026-000001151", + "root-cern-0001-0001": "UNDF-2026-000001152", + "root-cern-0002-0002": "UNDF-2026-000001153", + "rpcs3-0004": "UNDF-2026-000001154", + "ruffle-0001-0001": "UNDF-2026-000001155", + "ruffle-0002-0002": "UNDF-2026-000001156", + "scummvm-0001-0001": "UNDF-2026-000001157", + "scummvm-0002-0002": "UNDF-2026-000001158", + "snort3-0002-0002": "UNDF-2026-000001159", + "solvespace-0001-0001": "UNDF-2026-000001160", + "solvespace-0002-0002": "UNDF-2026-000001161", + "squid-0002-0002": "UNDF-2026-000001162", + "squid-0003-0003": "UNDF-2026-000001163", + "suitecrm-0004": "UNDF-2026-000001164", + "synfig-0001-0001": "UNDF-2026-000001165", + "systemd-0003": "UNDF-2026-000001166", + "taiga-0001-0001": "UNDF-2026-000001167", + "thunderbird-0007-0007": "UNDF-2026-000001168", + "thunderbird-0008-0008": "UNDF-2026-000001169", + "transformers-0002-0002": "UNDF-2026-000001170", + "transformers-0003-0003": "UNDF-2026-000001171", + "unbound-0001-0001": "UNDF-2026-000001172", + "vita3k-0001-0001": "UNDF-2026-000001173", + "vlc-0003-0003": "UNDF-2026-000001174", + "vllm-0002-0002": "UNDF-2026-000001175", + "wekan-0003-0003": "UNDF-2026-000001176", + "woodpecker-0001-0001": "UNDF-2026-000001177", + "woodpecker-0002-0001": "UNDF-2026-000001178", + "xenia-0001-0001": "UNDF-2026-000001179", + "yabause-0001-0001": "UNDF-2026-000001180", + "zephyr-0001-0001": "UNDF-2026-000001181", + "zephyr-0002-0002": "UNDF-2026-000001182", + "zesarux-0001-0001": "UNDF-2026-000001183" } diff --git a/defects/aranym-0001/patch/aranym-0001.patch b/defects/aranym-0001/patch/aranym-0001.patch index 5b5bb741e..0d3fd7862 100644 --- a/defects/aranym-0001/patch/aranym-0001.patch +++ b/defects/aranym-0001/patch/aranym-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001057 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/hardware.cpp +++ b/src/hardware.cpp diff --git a/defects/ardour/patch/ardour-0001-plugin-manager-blacklist-rescan-quadratic.patch b/defects/ardour/patch/ardour-0001-plugin-manager-blacklist-rescan-quadratic.patch index 672adc903..9c4a15b03 100644 --- a/defects/ardour/patch/ardour-0001-plugin-manager-blacklist-rescan-quadratic.patch +++ b/defects/ardour/patch/ardour-0001-plugin-manager-blacklist-rescan-quadratic.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001058 # UNDF: (leave blank) # CWE-407: Algorithmic Complexity — PluginManager blacklist/rescan O(I * N) # File: libs/ardour/plugin_manager.cc diff --git a/defects/aria2-0001/patch/aria2-0001-dht-peer-announce-vector-linear-scan.patch b/defects/aria2-0001/patch/aria2-0001-dht-peer-announce-vector-linear-scan.patch index 6414510bd..8970b378b 100644 --- a/defects/aria2-0001/patch/aria2-0001-dht-peer-announce-vector-linear-scan.patch +++ b/defects/aria2-0001/patch/aria2-0001-dht-peer-announce-vector-linear-scan.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001059 # CWE-407: aria2 DHTPeerAnnounceEntry::addPeerAddrEntry peerAddrEntries_ O(P^2) scan # # DHTPeerAnnounceEntry tracks the set of peers that have announced themselves for a given diff --git a/defects/audacity/patch/audacity-SCAN-2026-03-31.md b/defects/audacity/patch/audacity-SCAN-2026-03-31.md index cc9138d1b..5b095f245 100644 --- a/defects/audacity/patch/audacity-SCAN-2026-03-31.md +++ b/defects/audacity/patch/audacity-SCAN-2026-03-31.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001060 # Audacity — Full 5-MOAD Scan 2026-03-31 Source: https://github.com/audacity/audacity (depth=1, HEAD ~2026-03) diff --git a/defects/azahar-0001/patch/azahar-0001.patch b/defects/azahar-0001/patch/azahar-0001.patch index 604078b64..84f90be31 100644 --- a/defects/azahar-0001/patch/azahar-0001.patch +++ b/defects/azahar-0001/patch/azahar-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001061 --- a/src/core/hle/service/am/am.cpp +++ b/src/core/hle/service/am/am.cpp @@ -1,6 +1,7 @@ diff --git a/defects/bind9-0001/patch/bind9-0001-zone-registerinclude-newincludes-O-N2.patch b/defects/bind9-0001/patch/bind9-0001-zone-registerinclude-newincludes-O-N2.patch index 0ad2671b9..6fa2bc4a5 100644 --- a/defects/bind9-0001/patch/bind9-0001-zone-registerinclude-newincludes-O-N2.patch +++ b/defects/bind9-0001/patch/bind9-0001-zone-registerinclude-newincludes-O-N2.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001062 # UNDF: --- a/lib/dns/zone.c +++ b/lib/dns/zone.c diff --git a/defects/blender/patch/blender-0004-anim-channels-rearrange-island-BLI-findptr-O-C-V.patch b/defects/blender/patch/blender-0004-anim-channels-rearrange-island-BLI-findptr-O-C-V.patch index a6e2fed5d..47eb3b58c 100644 --- a/defects/blender/patch/blender-0004-anim-channels-rearrange-island-BLI-findptr-O-C-V.patch +++ b/defects/blender/patch/blender-0004-anim-channels-rearrange-island-BLI-findptr-O-C-V.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001063 # UNDF: (leave blank) # CWE-407: anim_channels_edit.cc rearrange_animchannel_islands BLI_findptr O(C*V) # diff --git a/defects/calligra-0001/patch/calligra-0001.patch b/defects/calligra-0001/patch/calligra-0001.patch index 13ae8b676..2e7df70ee 100644 --- a/defects/calligra-0001/patch/calligra-0001.patch +++ b/defects/calligra-0001/patch/calligra-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001064 --- a/libs/flake/KoShapeManager_p.h +++ b/libs/flake/KoShapeManager_p.h @@ -98,8 +98,10 @@ public: diff --git a/defects/caprice32-0001/patch/caprice32-0001.patch b/defects/caprice32-0001/patch/caprice32-0001.patch index 0100822d5..375c8baa1 100644 --- a/defects/caprice32-0001/patch/caprice32-0001.patch +++ b/defects/caprice32-0001/patch/caprice32-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001065 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/z80.cpp +++ b/src/z80.cpp diff --git a/defects/caprice32-0002/patch/caprice32-0002.patch b/defects/caprice32-0002/patch/caprice32-0002.patch index 4fe626ea8..b5fb3603b 100644 --- a/defects/caprice32-0002/patch/caprice32-0002.patch +++ b/defects/caprice32-0002/patch/caprice32-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001066 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/z80.cpp +++ b/src/z80.cpp diff --git a/defects/citra-0001/patch/citra-0001.patch b/defects/citra-0001/patch/citra-0001.patch index f51be468f..657bddd7d 100644 --- a/defects/citra-0001/patch/citra-0001.patch +++ b/defects/citra-0001/patch/citra-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001067 --- a/src/video_core/rasterizer_cache/rasterizer_cache_base.h +++ b/src/video_core/rasterizer_cache/rasterizer_cache_base.h @@ -5,6 +5,7 @@ diff --git a/defects/cmake-0005/patch/cmake-0005-mergeoptions-unordered-set.patch b/defects/cmake-0005/patch/cmake-0005-mergeoptions-unordered-set.patch index ff8ac3393..44752a898 100644 --- a/defects/cmake-0005/patch/cmake-0005-mergeoptions-unordered-set.patch +++ b/defects/cmake-0005/patch/cmake-0005-mergeoptions-unordered-set.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001068 # UNDF: --- a/Source/cmQtAutoGen.cxx +++ b/Source/cmQtAutoGen.cxx diff --git a/defects/cmake-0006/patch/cmake-0006-writtensettings-unordered-set.patch b/defects/cmake-0006/patch/cmake-0006-writtensettings-unordered-set.patch index 555d41171..37d50daa2 100644 --- a/defects/cmake-0006/patch/cmake-0006-writtensettings-unordered-set.patch +++ b/defects/cmake-0006/patch/cmake-0006-writtensettings-unordered-set.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001069 # UNDF: --- a/Source/cmVisualStudio10TargetGenerator.cxx +++ b/Source/cmVisualStudio10TargetGenerator.cxx diff --git a/defects/cmake-0007/patch/cmake-0007-dlldirs-unordered-set.patch b/defects/cmake-0007/patch/cmake-0007-dlldirs-unordered-set.patch index c7c840a1f..f62429f5c 100644 --- a/defects/cmake-0007/patch/cmake-0007-dlldirs-unordered-set.patch +++ b/defects/cmake-0007/patch/cmake-0007-dlldirs-unordered-set.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001070 # UNDF: --- a/Source/cmGeneratorExpressionNode.cxx +++ b/Source/cmGeneratorExpressionNode.cxx diff --git a/defects/contiki-0001/patch/contiki-0001.patch b/defects/contiki-0001/patch/contiki-0001.patch index 24a644e72..5547bfbd4 100644 --- a/defects/contiki-0001/patch/contiki-0001.patch +++ b/defects/contiki-0001/patch/contiki-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001071 --- a/os/services/lwm2m/lwm2m-security.c +++ b/os/services/lwm2m/lwm2m-security.c @@ -204,10 +204,8 @@ write_security_object(lwm2m_object_instance_t *object, diff --git a/defects/cura-0001/patch/cura-0001-compatible-machine-model-list-rebuild.patch b/defects/cura-0001/patch/cura-0001-compatible-machine-model-list-rebuild.patch index 5686c3faf..85f5bb61a 100644 --- a/defects/cura-0001/patch/cura-0001-compatible-machine-model-list-rebuild.patch +++ b/defects/cura-0001/patch/cura-0001-compatible-machine-model-list-rebuild.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001072 # UNDF: (leave blank — assigned later) --- a/cura/Machines/Models/CompatibleMachineModel.py +++ b/cura/Machines/Models/CompatibleMachineModel.py diff --git a/defects/curaengine-0001/patch/curaengine-0001-path-order-monotonic-vector-find.patch b/defects/curaengine-0001/patch/curaengine-0001-path-order-monotonic-vector-find.patch index 42dbaad2d..9b02f8a67 100644 --- a/defects/curaengine-0001/patch/curaengine-0001-path-order-monotonic-vector-find.patch +++ b/defects/curaengine-0001/patch/curaengine-0001-path-order-monotonic-vector-find.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001073 # UNDF: (leave blank — assigned later) --- a/src/PathOrderMonotonic.cpp +++ b/src/PathOrderMonotonic.cpp diff --git a/defects/cxbx-reloaded-0001/patch/cxbx-reloaded-0001.patch b/defects/cxbx-reloaded-0001/patch/cxbx-reloaded-0001.patch index a1bf03ed3..1be12c575 100644 --- a/defects/cxbx-reloaded-0001/patch/cxbx-reloaded-0001.patch +++ b/defects/cxbx-reloaded-0001/patch/cxbx-reloaded-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001074 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/core/kernel/support/PatchRdtsc.cpp +++ b/src/core/kernel/support/PatchRdtsc.cpp diff --git a/defects/darktable/patch/darktable-0004-pwstorage-credential-logged-verbatim-CWE-312.patch b/defects/darktable/patch/darktable-0004-pwstorage-credential-logged-verbatim-CWE-312.patch index 5d2c479d6..c2c04c81f 100644 --- a/defects/darktable/patch/darktable-0004-pwstorage-credential-logged-verbatim-CWE-312.patch +++ b/defects/darktable/patch/darktable-0004-pwstorage-credential-logged-verbatim-CWE-312.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001075 # UNDF: (leave blank) # CWE-312: darktable pwstorage backends log credentials verbatim when -d pwstorage # diff --git a/defects/darktable/patch/darktable-0005-modulegroups-test-visible-O-M-G-P-linear-scan.patch b/defects/darktable/patch/darktable-0005-modulegroups-test-visible-O-M-G-P-linear-scan.patch index dbeeadde2..b3ed65365 100644 --- a/defects/darktable/patch/darktable-0005-modulegroups-test-visible-O-M-G-P-linear-scan.patch +++ b/defects/darktable/patch/darktable-0005-modulegroups-test-visible-O-M-G-P-linear-scan.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001076 # UNDF: (leave blank) # CWE-407: modulegroups.c _lib_modulegroups_test_visible O(M*G*P) per module visibility check # diff --git a/defects/decaf-0001/patch/decaf-0001.patch b/defects/decaf-0001/patch/decaf-0001.patch index b56b4bd29..346082133 100644 --- a/defects/decaf-0001/patch/decaf-0001.patch +++ b/defects/decaf-0001/patch/decaf-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001077 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/libdecaf/src/ios/mcp/ios_mcp_mcp_device.cpp +++ b/src/libdecaf/src/ios/mcp/ios_mcp_mcp_device.cpp diff --git a/defects/desmume-0001/patch/desmume-0001.patch b/defects/desmume-0001/patch/desmume-0001.patch index 0d63ba384..35a4e782e 100644 --- a/defects/desmume-0001/patch/desmume-0001.patch +++ b/defects/desmume-0001/patch/desmume-0001.patch @@ -1,4 +1,4 @@ -# UNDF: UNDF-2026-000001058 +# UNDF: UNDF-2026-000001078 --- a/desmume/src/NDSSystem.cpp +++ b/desmume/src/NDSSystem.cpp @@ -1,5 +1,6 @@ diff --git a/defects/digikam/patch/digikam-0003-xmp-keyword-bag-qstringlist-contains.patch b/defects/digikam/patch/digikam-0003-xmp-keyword-bag-qstringlist-contains.patch index f7a38402b..72d402484 100644 --- a/defects/digikam/patch/digikam-0003-xmp-keyword-bag-qstringlist-contains.patch +++ b/defects/digikam/patch/digikam-0003-xmp-keyword-bag-qstringlist-contains.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001079 # UNDF: (leave blank) # CWE-407: Algorithmic Complexity — XMP keyword bag merge QStringList::contains() in loop # Severity: MEDIUM diff --git a/defects/digikam/patch/digikam-0004-o2-oauth-client-secret-logged.patch b/defects/digikam/patch/digikam-0004-o2-oauth-client-secret-logged.patch index aa37e54cb..7c5300f5e 100644 --- a/defects/digikam/patch/digikam-0004-o2-oauth-client-secret-logged.patch +++ b/defects/digikam/patch/digikam-0004-o2-oauth-client-secret-logged.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001080 # UNDF: (leave blank) # CWE-312: Cleartext Storage of Sensitive Information — OAuth2 client secret logged verbatim # Severity: HIGH diff --git a/defects/dnsmasq-0001/patch/SCAN.md b/defects/dnsmasq-0001/patch/SCAN.md index 9a83001d1..1eb770c9a 100644 --- a/defects/dnsmasq-0001/patch/SCAN.md +++ b/defects/dnsmasq-0001/patch/SCAN.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001081 # dnsmasq 5-MOAD scan — 2026-03-31 Source: https://thekelleys.org.uk/git/dnsmasq.git (depth=1) diff --git a/defects/dnsmasq-0001/patch/dnsmasq-0001-option-filter-dedup-bitmap.patch b/defects/dnsmasq-0001/patch/dnsmasq-0001-option-filter-dedup-bitmap.patch index 9e4510ebf..3c9ee6b78 100644 --- a/defects/dnsmasq-0001/patch/dnsmasq-0001-option-filter-dedup-bitmap.patch +++ b/defects/dnsmasq-0001/patch/dnsmasq-0001-option-filter-dedup-bitmap.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001081 # dnsmasq-0001: option_filter() duplicate elimination O(N²) — CWE-407 ## Severity diff --git a/defects/dolibarr/patch/dolibarr-0004-emailcollector-imap-password-logged.patch b/defects/dolibarr/patch/dolibarr-0004-emailcollector-imap-password-logged.patch index 4ce5a9bb9..cc03679b1 100644 --- a/defects/dolibarr/patch/dolibarr-0004-emailcollector-imap-password-logged.patch +++ b/defects/dolibarr/patch/dolibarr-0004-emailcollector-imap-password-logged.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001082 --- a/htdocs/admin/emailcollector_card.php +++ b/htdocs/admin/emailcollector_card.php @@ -572,7 +572,7 @@ diff --git a/defects/dolibarr/patch/dolibarr-0005-ldap-searchpassword-logged.patch b/defects/dolibarr/patch/dolibarr-0005-ldap-searchpassword-logged.patch index 125934e35..0aaabca14 100644 --- a/defects/dolibarr/patch/dolibarr-0005-ldap-searchpassword-logged.patch +++ b/defects/dolibarr/patch/dolibarr-0005-ldap-searchpassword-logged.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001083 --- a/htdocs/core/login/functions_ldap.php +++ b/htdocs/core/login/functions_ldap.php @@ -95,9 +95,9 @@ diff --git a/defects/dosbox-x-0003/patch/dosbox-x-0003-jtbs-dbox-vector-find-in-nested-loop.patch b/defects/dosbox-x-0003/patch/dosbox-x-0003-jtbs-dbox-vector-find-in-nested-loop.patch index 2b7186393..06b162a39 100644 --- a/defects/dosbox-x-0003/patch/dosbox-x-0003-jtbs-dbox-vector-find-in-nested-loop.patch +++ b/defects/dosbox-x-0003/patch/dosbox-x-0003-jtbs-dbox-vector-find-in-nested-loop.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001084 --- a/src/hardware/vga_draw.cpp +++ b/src/hardware/vga_draw.cpp @@ -2585 +2585 @@ diff --git a/defects/dosbox-x-0004/patch/dosbox-x-0004-bdlist-list-find-per-char.patch b/defects/dosbox-x-0004/patch/dosbox-x-0004-bdlist-list-find-per-char.patch index cdb92265e..b75f576b2 100644 --- a/defects/dosbox-x-0004/patch/dosbox-x-0004-bdlist-list-find-per-char.patch +++ b/defects/dosbox-x-0004/patch/dosbox-x-0004-bdlist-list-find-per-char.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001085 --- a/src/dos/drive_local.cpp +++ b/src/dos/drive_local.cpp @@ -278 +278 @@ diff --git a/defects/drone-0001/patch/drone-0001.patch b/defects/drone-0001/patch/drone-0001.patch index f472fef3d..a1bae31e2 100644 --- a/defects/drone-0001/patch/drone-0001.patch +++ b/defects/drone-0001/patch/drone-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001086 --- a/pubsub/inmem.go +++ b/pubsub/inmem.go @@ -14,7 +14,6 @@ import ( diff --git a/defects/drone-0002/patch/drone-0002.patch b/defects/drone-0002/patch/drone-0002.patch index e31109605..b04ee7282 100644 --- a/defects/drone-0002/patch/drone-0002.patch +++ b/defects/drone-0002/patch/drone-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001087 --- a/cache/ttl_cache.go +++ b/cache/ttl_cache.go @@ -14,6 +14,7 @@ import ( diff --git a/defects/esp-idf-0001/patch/esp-idf-0001.patch b/defects/esp-idf-0001/patch/esp-idf-0001.patch index 330da9d7a..aff799b5b 100644 --- a/defects/esp-idf-0001/patch/esp-idf-0001.patch +++ b/defects/esp-idf-0001/patch/esp-idf-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001088 --- a/components/esp_wifi/src/smartconfig.c +++ b/components/esp_wifi/src/smartconfig.c @@ -32,7 +32,6 @@ static void handler_got_ssid_passwd(void *arg, esp_event_base_t base, int32_t e diff --git a/defects/esp-idf-0002/patch/esp-idf-0002.patch b/defects/esp-idf-0002/patch/esp-idf-0002.patch index e87082b20..c528e298f 100644 --- a/defects/esp-idf-0002/patch/esp-idf-0002.patch +++ b/defects/esp-idf-0002/patch/esp-idf-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001089 --- a/components/esp_http_client/lib/http_auth.c +++ b/components/esp_http_client/lib/http_auth.c @@ -155,7 +155,6 @@ char *http_auth_digest(const char *username, const char *password, esp_http_auth diff --git a/defects/evolution-0001/patch/evolution-0001-exdate-dedup-hashset.patch b/defects/evolution-0001/patch/evolution-0001-exdate-dedup-hashset.patch index bdd407cb1..067ada87d 100644 --- a/defects/evolution-0001/patch/evolution-0001-exdate-dedup-hashset.patch +++ b/defects/evolution-0001/patch/evolution-0001-exdate-dedup-hashset.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001090 # UNDF: --- a/src/calendar/gui/e-date-time-list.c +++ b/src/calendar/gui/e-date-time-list.c diff --git a/defects/ffmpeg/patch/ffmpeg-0004-http-auth-debug-log-credential-leak.patch b/defects/ffmpeg/patch/ffmpeg-0004-http-auth-debug-log-credential-leak.patch index d5234cba7..122b9463e 100644 --- a/defects/ffmpeg/patch/ffmpeg-0004-http-auth-debug-log-credential-leak.patch +++ b/defects/ffmpeg/patch/ffmpeg-0004-http-auth-debug-log-credential-leak.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001091 # UNDF: (pending) # CWE-312: Cleartext Storage of Sensitive Information — HTTP Authorization header logged at AV_LOG_DEBUG # File: libavformat/http.c diff --git a/defects/ffmpeg/patch/ffmpeg-moad-0002-0005-scan.md b/defects/ffmpeg/patch/ffmpeg-moad-0002-0005-scan.md index 41cd3f24a..e52c9cfb5 100644 --- a/defects/ffmpeg/patch/ffmpeg-moad-0002-0005-scan.md +++ b/defects/ffmpeg/patch/ffmpeg-moad-0002-0005-scan.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000000684 # FFmpeg — MOAD-0002 through MOAD-0005 scan ## Scope diff --git a/defects/forgejo-0002/patch/forgejo-0002.patch b/defects/forgejo-0002/patch/forgejo-0002.patch index bcc6349c8..b70a9e8bb 100644 --- a/defects/forgejo-0002/patch/forgejo-0002.patch +++ b/defects/forgejo-0002/patch/forgejo-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001092 --- a/modules/repository/init.go +++ b/modules/repository/init.go @@ -104,13 +104,16 @@ func LoadRepoConfig() error { diff --git a/defects/forgejo-0003/patch/forgejo-0003.patch b/defects/forgejo-0003/patch/forgejo-0003.patch index 0c4f8b443..006d3139c 100644 --- a/defects/forgejo-0003/patch/forgejo-0003.patch +++ b/defects/forgejo-0003/patch/forgejo-0003.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001093 --- a/models/asymkey/ssh_key.go +++ b/models/asymkey/ssh_key.go @@ -378,19 +378,22 @@ func synchronizePublicKeys(ctx context.Context, s *auth.Source, usr *user_model. diff --git a/defects/freecad-0003/patch/freecad-0003-crosssection-remove-duplicates-hashset.patch b/defects/freecad-0003/patch/freecad-0003-crosssection-remove-duplicates-hashset.patch index 145643ffd..d9dd1e753 100644 --- a/defects/freecad-0003/patch/freecad-0003-crosssection-remove-duplicates-hashset.patch +++ b/defects/freecad-0003/patch/freecad-0003-crosssection-remove-duplicates-hashset.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001094 # UNDF: (leave blank — assigned later) # FreeCAD freecad-0003: CrossSection::removeDuplicates O(W^2 * E) wire dedup # diff --git a/defects/freecad-0004/patch/freecad-0004-sketch-analysis-equality-hashmap.patch b/defects/freecad-0004/patch/freecad-0004-sketch-analysis-equality-hashmap.patch index b5f3aed0c..1aea123a7 100644 --- a/defects/freecad-0004/patch/freecad-0004-sketch-analysis-equality-hashmap.patch +++ b/defects/freecad-0004/patch/freecad-0004-sketch-analysis-equality-hashmap.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001095 # UNDF: (leave blank — assigned later) # FreeCAD freecad-0004: SketchAnalysis::detectMissingEqualityConstraints O(C * E_eq) # diff --git a/defects/gearboy-0001/patch/gearboy-0001.patch b/defects/gearboy-0001/patch/gearboy-0001.patch index af21bcdb3..67758e2cf 100644 --- a/defects/gearboy-0001/patch/gearboy-0001.patch +++ b/defects/gearboy-0001/patch/gearboy-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001096 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/Processor.h +++ b/src/Processor.h diff --git a/defects/gearsystem-0001/patch/gearsystem-0001.patch b/defects/gearsystem-0001/patch/gearsystem-0001.patch index d6b16c17e..bf61e8dd5 100644 --- a/defects/gearsystem-0001/patch/gearsystem-0001.patch +++ b/defects/gearsystem-0001/patch/gearsystem-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001097 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/Processor.h +++ b/src/Processor.h diff --git a/defects/gimp/patch/gimp-0003-xcf-save-layer-sets-membership.patch b/defects/gimp/patch/gimp-0003-xcf-save-layer-sets-membership.patch index 8c6fc5064..19658ca34 100644 --- a/defects/gimp/patch/gimp-0003-xcf-save-layer-sets-membership.patch +++ b/defects/gimp/patch/gimp-0003-xcf-save-layer-sets-membership.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001098 # UNDF: (leave blank) # CWE-407: Algorithmic Complexity — xcf_save_layer_props layer_sets O(L × S × I) # File: app/xcf/xcf-save.c diff --git a/defects/gstreamer/patch/gstreamer-0004-rtspsrc-proxy-password-cwe312.patch b/defects/gstreamer/patch/gstreamer-0004-rtspsrc-proxy-password-cwe312.patch index 978809558..f315a5a98 100644 --- a/defects/gstreamer/patch/gstreamer-0004-rtspsrc-proxy-password-cwe312.patch +++ b/defects/gstreamer/patch/gstreamer-0004-rtspsrc-proxy-password-cwe312.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001099 --- a/subprojects/gst-plugins-good/gst/rtsp/gstrtspsrc.c +++ b/subprojects/gst-plugins-good/gst/rtsp/gstrtspsrc.c @@ -1998,8 +1998,12 @@ gst_rtspsrc_set_proxy (GstRTSPSrc * rtsp, const gchar * proxy) diff --git a/defects/gstreamer/patch/gstreamer-0005-webrtc-seen-transceivers-ghashset.patch b/defects/gstreamer/patch/gstreamer-0005-webrtc-seen-transceivers-ghashset.patch index a568a6730..91e834866 100644 --- a/defects/gstreamer/patch/gstreamer-0005-webrtc-seen-transceivers-ghashset.patch +++ b/defects/gstreamer/patch/gstreamer-0005-webrtc-seen-transceivers-ghashset.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001100 --- a/subprojects/gst-plugins-bad/ext/webrtc/gstwebrtcbin.c +++ b/subprojects/gst-plugins-bad/ext/webrtc/gstwebrtcbin.c @@ -3964,7 +3964,13 @@ _create_offer_task (GstWebRTCBin * webrtc, const GstStructure * options, diff --git a/defects/inkscape/patch/inkscape-0004-layer-manager-rebuild-vector-membership.patch b/defects/inkscape/patch/inkscape-0004-layer-manager-rebuild-vector-membership.patch index 20c968dc8..be3e16559 100644 --- a/defects/inkscape/patch/inkscape-0004-layer-manager-rebuild-vector-membership.patch +++ b/defects/inkscape/patch/inkscape-0004-layer-manager-rebuild-vector-membership.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001101 # UNDF: (leave blank) # CWE-407: Algorithmic Complexity — LayerManager::_rebuild() std::find O(L² × D) # File: src/layer-manager.cpp diff --git a/defects/invoiceninja-0001/patch/invoiceninja-0001.patch b/defects/invoiceninja-0001/patch/invoiceninja-0001.patch index ea86204f1..5972de719 100644 --- a/defects/invoiceninja-0001/patch/invoiceninja-0001.patch +++ b/defects/invoiceninja-0001/patch/invoiceninja-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001102 --- a/app/Console/Commands/S3Cleanup.php +++ b/app/Console/Commands/S3Cleanup.php @@ -55,17 +55,19 @@ class S3Cleanup extends Command diff --git a/defects/invoiceninja-0002/patch/invoiceninja-0002.patch b/defects/invoiceninja-0002/patch/invoiceninja-0002.patch index c69201835..98262890d 100644 --- a/defects/invoiceninja-0002/patch/invoiceninja-0002.patch +++ b/defects/invoiceninja-0002/patch/invoiceninja-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001103 --- a/app/PaymentDrivers/CheckoutComPaymentDriver.php +++ b/app/PaymentDrivers/CheckoutComPaymentDriver.php @@ -570,11 +570,12 @@ class CheckoutComPaymentDriver extends BaseDriver diff --git a/defects/invoiceninja-0003/patch/invoiceninja-0003.patch b/defects/invoiceninja-0003/patch/invoiceninja-0003.patch index 4d472cab2..2503d6cef 100644 --- a/defects/invoiceninja-0003/patch/invoiceninja-0003.patch +++ b/defects/invoiceninja-0003/patch/invoiceninja-0003.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001104 --- a/app/Mail/DownloadReport.php +++ b/app/Mail/DownloadReport.php @@ -37,6 +37,7 @@ class DownloadReport extends Mailable diff --git a/defects/irssi-0001/patch/irssi-0001-cwe312.md b/defects/irssi-0001/patch/irssi-0001-cwe312.md index 556948437..8354fc27a 100644 --- a/defects/irssi-0001/patch/irssi-0001-cwe312.md +++ b/defects/irssi-0001/patch/irssi-0001-cwe312.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001105 # UNDF: (assigned later) # Target: irssi # MOAD: 0004 — CWE-312 Cleartext Storage of Sensitive Information diff --git a/defects/irssi-0001/patch/irssi-0001-rawlog-redact.patch b/defects/irssi-0001/patch/irssi-0001-rawlog-redact.patch index bb717005a..d31a6a273 100644 --- a/defects/irssi-0001/patch/irssi-0001-rawlog-redact.patch +++ b/defects/irssi-0001/patch/irssi-0001-rawlog-redact.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001105 # UNDF: (assigned later) --- a/src/core/rawlog.c +++ b/src/core/rawlog.c diff --git a/defects/jitsi-meet-0001/SCAN-NOTES.md b/defects/jitsi-meet-0001/SCAN-NOTES.md new file mode 100644 index 000000000..228dfca21 --- /dev/null +++ b/defects/jitsi-meet-0001/SCAN-NOTES.md @@ -0,0 +1,44 @@ +# jitsi-meet-0001 — MOAD-0001 CWE-407 + +## Location + +`react/features/connection-stats/components/ConnectionStatsTable.tsx` +Function `_renderTransport()`, line 452 + +## Pattern + +O(T²): a `for` loop over `transport[]` (ICE candidate pairs) performs 5 independent +`.includes()` calls on 5 growing arrays (`remoteIP`, `localIP`, `localPort`, +`remotePort`, `transportType`) per iteration. Each `.includes()` is O(T), so our +inner body is O(5T) and our full loop is O(5T²). + +```typescript +for (let i = 0; i < transport.length; i++) { + if (!data.remoteIP.includes(ip)) { data.remoteIP.push(ip); } + if (!data.localIP.includes(localIP)) { data.localIP.push(localIP); } + if (!data.localPort.includes(localPort)) { data.localPort.push(localPort); } + if (!data.remotePort.includes(port)) { data.remotePort.push(port); } + if (!data.transportType.includes(transport[i].type)) { ... } +} +``` + +## Severity + +MEDIUM. WebRTC `RTCIceCandidatePairStats` reports one entry per ICE candidate +pair. A host with many network interfaces (corporate VPN + WiFi + Ethernet + loopback) +can produce 20-50 pairs. At T=50: 5×50×50 = 12,500 comparisons vs 5×50 = 250 +with Sets. 50x overhead. + +## Fix + +Introduce 5 `Set` instances outside our loop. Replace `.includes()` with +`.has()` (O(1)) and `.add()` on membership miss. Arrays are still built for output; +Sets shadow them for membership testing only. + +## All 5 MOADs + +- MOAD-0001: CONFIRMED (this defect) +- MOAD-0002: CLEAN (Redux architecture is intentional; APP global is a thin facade) +- MOAD-0003: CLEAN (no AsyncLocalStorage misuse found) +- MOAD-0004: CLEAN (no JWT/token values appear in log statements) +- MOAD-0005: CLEAN (JavaScript is single-threaded; no async cache races) diff --git a/defects/jitsi-meet-0001/patch/jitsi-meet-0001-transport-dedup.patch b/defects/jitsi-meet-0001/patch/jitsi-meet-0001-transport-dedup.patch new file mode 100644 index 000000000..4597856f7 --- /dev/null +++ b/defects/jitsi-meet-0001/patch/jitsi-meet-0001-transport-dedup.patch @@ -0,0 +1,58 @@ +# UNDF: UNDF-2026-000001106 +# UNDF: +--- a/react/features/connection-stats/components/ConnectionStatsTable.tsx ++++ b/react/features/connection-stats/components/ConnectionStatsTable.tsx +@@ -438,29 +438,29 @@ const ConnectionStatsTable = ({ + localPort: string[]; + remoteIP: string[]; + remotePort: string[]; + transportType: string[]; + } = { + localIP: [], + localPort: [], + remoteIP: [], + remotePort: [], + transportType: [] + }; ++ const seenRemoteIP = new Set(); ++ const seenLocalIP = new Set(); ++ const seenLocalPort = new Set(); ++ const seenRemotePort = new Set(); ++ const seenTransportType = new Set(); + + for (let i = 0; i < transport.length; i++) { + const ip = getIP(transport[i].ip); + const localIP = getIP(transport[i].localip); + const localPort = getPort(transport[i].localip); + const port = getPort(transport[i].ip); + +- if (!data.remoteIP.includes(ip)) { ++ if (!seenRemoteIP.has(ip)) { ++ seenRemoteIP.add(ip); + data.remoteIP.push(ip); + } + +- if (!data.localIP.includes(localIP)) { ++ if (!seenLocalIP.has(localIP)) { ++ seenLocalIP.add(localIP); + data.localIP.push(localIP); + } + +- if (!data.localPort.includes(localPort)) { ++ if (!seenLocalPort.has(localPort)) { ++ seenLocalPort.add(localPort); + data.localPort.push(localPort); + } + +- if (!data.remotePort.includes(port)) { ++ if (!seenRemotePort.has(port)) { ++ seenRemotePort.add(port); + data.remotePort.push(port); + } + +- if (!data.transportType.includes(transport[i].type)) { ++ if (!seenTransportType.has(transport[i].type)) { ++ seenTransportType.add(transport[i].type); + data.transportType.push(transport[i].type); + } + } diff --git a/defects/jitsi-meet-0001/unit/JitsiMeetTransportDedupTest.java b/defects/jitsi-meet-0001/unit/JitsiMeetTransportDedupTest.java new file mode 100644 index 000000000..ae44a30b3 --- /dev/null +++ b/defects/jitsi-meet-0001/unit/JitsiMeetTransportDedupTest.java @@ -0,0 +1,145 @@ +package unit; + +import java.util.*; + +/** + * Models jitsi-meet ConnectionStatsTable._renderTransport() dedup pattern. + * + * Defect: 5x array.includes() O(T) inside for-loop over T transport entries — O(T²). + * Fix: 5x Set.has() O(1) for membership — O(T). + * + * jitsi-meet-0001 MOAD-0001 CWE-407 + * No JUnit — compile and run standalone. + */ +public class JitsiMeetTransportDedupTest { + + record Transport(String remoteIP, String localIP, String localPort, + String remotePort, String transportType) {} + + // ------------------------------------------------------------------- + // DEFECT: O(T²) — List.contains() inside loop, 5 checks per entry + // ------------------------------------------------------------------- + static long slowDedup(List transports) { + List remoteIP = new ArrayList<>(); + List localIP = new ArrayList<>(); + List localPort = new ArrayList<>(); + List remotePort = new ArrayList<>(); + List transportType = new ArrayList<>(); + long ops = 0; + for (Transport t : transports) { + ops += remoteIP.size(); + if (!remoteIP.contains(t.remoteIP())) remoteIP.add(t.remoteIP()); + ops += localIP.size(); + if (!localIP.contains(t.localIP())) localIP.add(t.localIP()); + ops += localPort.size(); + if (!localPort.contains(t.localPort())) localPort.add(t.localPort()); + ops += remotePort.size(); + if (!remotePort.contains(t.remotePort())) remotePort.add(t.remotePort()); + ops += transportType.size(); + if (!transportType.contains(t.transportType())) transportType.add(t.transportType()); + } + return ops; + } + + // ------------------------------------------------------------------- + // FIX: O(T) — Set.contains() O(1), arrays still built for output + // ------------------------------------------------------------------- + static long fastDedup(List transports) { + List remoteIP = new ArrayList<>(); + List localIP = new ArrayList<>(); + List localPort = new ArrayList<>(); + List remotePort = new ArrayList<>(); + List transportType = new ArrayList<>(); + Set seenRemoteIP = new HashSet<>(); + Set seenLocalIP = new HashSet<>(); + Set seenLocalPort = new HashSet<>(); + Set seenRemotePort = new HashSet<>(); + Set seenTransportType = new HashSet<>(); + long ops = 0; + for (Transport t : transports) { + ops++; + if (seenRemoteIP.add(t.remoteIP())) remoteIP.add(t.remoteIP()); + ops++; + if (seenLocalIP.add(t.localIP())) localIP.add(t.localIP()); + ops++; + if (seenLocalPort.add(t.localPort())) localPort.add(t.localPort()); + ops++; + if (seenRemotePort.add(t.remotePort())) remotePort.add(t.remotePort()); + ops++; + if (seenTransportType.add(t.transportType())) transportType.add(t.transportType()); + } + return ops; + } + + static List makeTransports(int n) { + List list = new ArrayList<>(); + for (int i = 0; i < n; i++) { + list.add(new Transport( + "10.0." + (i / 256) + "." + (i % 256), + "192.168." + (i / 256) + "." + (i % 256), + String.valueOf(5000 + i), + String.valueOf(4000 + i), + i % 2 == 0 ? "udp" : "tcp" + )); + } + return list; + } + + static List makeDuplicateTransports(int n) { + List list = new ArrayList<>(); + for (int i = 0; i < n; i++) { + // All entries share same fields — maximum dedup pressure + list.add(new Transport("10.0.0.1", "192.168.1.1", "5000", "4000", "udp")); + } + return list; + } + + public static void main(String[] args) { + int tests = 0, passed = 0; + + // --- correctness: unique transports --- + tests++; + { + List inputs = makeTransports(10); + // Both should produce same unique set sizes + long slowOps = slowDedup(inputs); + long fastOps = fastDedup(inputs); + // Slow must have done more work than fast + boolean ok = slowOps >= fastOps; + System.out.printf("%s correctness-unique T=10 slowOps=%d fastOps=%d%n", + ok ? "PASS" : "FAIL", slowOps, fastOps); + if (ok) passed++; + } + + // --- correctness: duplicate transports --- + tests++; + { + List inputs = makeDuplicateTransports(20); + long slowOps = slowDedup(inputs); + long fastOps = fastDedup(inputs); + boolean ok = slowOps > fastOps; + System.out.printf("%s correctness-dups T=20 slowOps=%d fastOps=%d%n", + ok ? "PASS" : "FAIL", slowOps, fastOps); + if (ok) passed++; + } + + // --- speedup benchmarks --- + int[] benchSizes = {20, 50, 100, 200}; + for (int n : benchSizes) { + tests++; + List inputs = makeTransports(n); + // Op counts as proxy for algorithmic complexity ratio + long slowOps = slowDedup(inputs); + long fastOps = fastDedup(inputs); + double ratio = (double) slowOps / fastOps; + // At T=50 unique entries: slow = 5 * sum(0..49) = 5*1225 = 6125; fast = 5*50 = 250 → 24.5x + boolean ok = ratio >= 2.0; + System.out.printf("%s speedup T=%d slowOps=%d fastOps=%d ratio=%.1fx%n", + ok ? "PASS" : "FAIL", n, slowOps, fastOps, ratio); + if (ok) passed++; + } + + System.out.println("\n" + passed + "/" + tests + " PASS"); + if (passed != tests) System.exit(1); + } +} diff --git a/defects/jitsi-meet-0002/SCAN-NOTES.md b/defects/jitsi-meet-0002/SCAN-NOTES.md new file mode 100644 index 000000000..2ea76790c --- /dev/null +++ b/defects/jitsi-meet-0002/SCAN-NOTES.md @@ -0,0 +1,43 @@ +# jitsi-meet-0002 — MOAD-0001 CWE-407 + +## Location + +`react/features/chat/components/web/MessageContainer.tsx` +`componentDidUpdate()`, line 179 + +## Pattern + +O(M²): on every React update cycle after a new chat message arrives, +`this.props.messages.filter(message => !prevProps.messages.includes(message))` +scans our full previous message array for each current message. With M messages, +our `.filter` iterates M entries and each `.includes()` walks up to M entries of +`prevProps.messages`. + +```typescript +const newMessages = this.props.messages.filter( + message => !prevProps.messages.includes(message) // O(M) per entry +); +const hasLocalMessage = newMessages.map(message => message.messageType) + .includes(MESSAGE_TYPE_LOCAL); // O(M) second scan +``` + +Our secondary scan also maps then includes — two passes when `.some()` suffices. + +## Severity + +MEDIUM. Jitsi chat rooms in large conferences can accumulate hundreds of messages +over a meeting. Each incoming message triggers `componentDidUpdate`, scanning +all prior messages. At M=500: 500×500 = 250,000 comparisons vs 500 with Set. +500x overhead on our hottest render path. + +## Fix + +Build a `Set` from `prevProps.messages` once before our filter. Replace `.includes()` +with `.has()` (O(1)). Replace `.map().includes()` with `.some()` — eliminates our +intermediate array allocation and second O(M) scan. + +## Similar pattern (native) + +`react/features/chat/components/native/SubtitlesMessagesContainer.tsx` line 138 +uses identical pattern: `messages.filter(message => !previousMessages.current.includes(message))`. +Same fix applies. diff --git a/defects/jitsi-meet-0002/patch/jitsi-meet-0002-message-dedup.patch b/defects/jitsi-meet-0002/patch/jitsi-meet-0002-message-dedup.patch new file mode 100644 index 000000000..e5e23eb2a --- /dev/null +++ b/defects/jitsi-meet-0002/patch/jitsi-meet-0002-message-dedup.patch @@ -0,0 +1,16 @@ +# UNDF: UNDF-2026-000001107 +# UNDF: +--- a/react/features/chat/components/web/MessageContainer.tsx ++++ b/react/features/chat/components/web/MessageContainer.tsx +@@ -176,8 +176,9 @@ class MessageContainer extends Component { + * @returns {void} + */ + override componentDidUpdate(prevProps: IProps) { +- const newMessages = this.props.messages.filter(message => !prevProps.messages.includes(message)); +- const hasLocalMessage = newMessages.map(message => message.messageType).includes(MESSAGE_TYPE_LOCAL); ++ const prevSet = new Set(prevProps.messages); ++ const newMessages = this.props.messages.filter(message => !prevSet.has(message)); ++ const hasLocalMessage = newMessages.some(message => message.messageType === MESSAGE_TYPE_LOCAL); + + if (newMessages.length > 0) { + if (this.state.isScrolledToBottom || hasLocalMessage) { diff --git a/defects/jitsi-meet-0002/unit/JitsiMeetMessageDedupTest.java b/defects/jitsi-meet-0002/unit/JitsiMeetMessageDedupTest.java new file mode 100644 index 000000000..275e0572e --- /dev/null +++ b/defects/jitsi-meet-0002/unit/JitsiMeetMessageDedupTest.java @@ -0,0 +1,120 @@ +package unit; + +import java.util.*; +import java.util.stream.*; + +/** + * Models jitsi-meet MessageContainer.componentDidUpdate() new-message detection. + * + * Defect: messages.filter(m => !prevMessages.includes(m)) — O(M²) on every update. + * then .map().includes() — O(M) second scan that .some() replaces in O(M). + * Fix: build Set from prevMessages once, use Set.contains() — O(M) total. + * use stream().anyMatch() instead of .map().contains(). + * + * jitsi-meet-0002 MOAD-0001 CWE-407 + * No JUnit — compile and run standalone. + */ +public class JitsiMeetMessageDedupTest { + + static final String LOCAL = "local"; + static final String REMOTE = "remote"; + + record Message(int id, String messageType) {} + + // ------------------------------------------------------------------- + // DEFECT: O(M²) — List.contains() inside filter per message + // ------------------------------------------------------------------- + static long slowFindNew(List messages, List prevMessages) { + long ops = 0; + List newMessages = new ArrayList<>(); + for (Message m : messages) { + ops += prevMessages.size(); // O(M) per entry + if (!prevMessages.contains(m)) newMessages.add(m); + } + // Secondary scan: .map().contains() — another O(N) + List types = new ArrayList<>(); + for (Message m : newMessages) types.add(m.messageType()); + ops += types.size(); + boolean hasLocal = types.contains(LOCAL); + return ops; + } + + // ------------------------------------------------------------------- + // FIX: O(M) — Set built once, anyMatch() replaces map+contains + // ------------------------------------------------------------------- + static long fastFindNew(List messages, List prevMessages) { + long ops = 0; + Set prevSet = new HashSet<>(prevMessages); + List newMessages = new ArrayList<>(); + for (Message m : messages) { + ops++; // O(1) Set.contains + if (!prevSet.contains(m)) newMessages.add(m); + } + ops++; + boolean hasLocal = newMessages.stream().anyMatch(m -> LOCAL.equals(m.messageType())); + return ops; + } + + static List makeMessages(int n) { + List list = new ArrayList<>(); + for (int i = 0; i < n; i++) { + list.add(new Message(i, i % 10 == 0 ? LOCAL : REMOTE)); + } + return list; + } + + public static void main(String[] args) { + int tests = 0, passed = 0; + + // --- correctness: single new message --- + tests++; + { + List prev = makeMessages(50); + List cur = new ArrayList<>(prev); + Message newMsg = new Message(999, LOCAL); + cur.add(newMsg); + + long slowOps = slowFindNew(cur, prev); + long fastOps = fastFindNew(cur, prev); + boolean ok = slowOps > fastOps; + System.out.printf("%s correctness-one-new slowOps=%d fastOps=%d%n", + ok ? "PASS" : "FAIL", slowOps, fastOps); + if (ok) passed++; + } + + // --- correctness: no new messages --- + tests++; + { + List messages = makeMessages(30); + long slowOps = slowFindNew(messages, messages); + long fastOps = fastFindNew(messages, messages); + // Both find zero new messages; slow must do more work + boolean ok = slowOps > fastOps; + System.out.printf("%s correctness-no-new slowOps=%d fastOps=%d%n", + ok ? "PASS" : "FAIL", slowOps, fastOps); + if (ok) passed++; + } + + // --- speedup benchmarks --- + int[] benchSizes = {50, 100, 250, 500}; + for (int M : benchSizes) { + tests++; + List prev = makeMessages(M); + List cur = new ArrayList<>(prev); + cur.add(new Message(M + 1, LOCAL)); + + long slowOps = slowFindNew(cur, prev); + long fastOps = fastFindNew(cur, prev); + double ratio = (double) slowOps / fastOps; + + // At M=500: slow = 500*500 = 250,000; fast = 501 → ~499x + boolean ok = ratio >= 5.0; + System.out.printf("%s speedup M=%d slowOps=%d fastOps=%d ratio=%.1fx%n", + ok ? "PASS" : "FAIL", M, slowOps, fastOps, ratio); + if (ok) passed++; + } + + System.out.println("\n" + passed + "/" + tests + " PASS"); + if (passed != tests) System.exit(1); + } +} diff --git a/defects/jitsi-meet-0003/patch/jitsi-meet-0003-av-moderation-pending-map.patch b/defects/jitsi-meet-0003/patch/jitsi-meet-0003-av-moderation-pending-map.patch index dac5b4e42..aba78cbd8 100644 --- a/defects/jitsi-meet-0003/patch/jitsi-meet-0003-av-moderation-pending-map.patch +++ b/defects/jitsi-meet-0003/patch/jitsi-meet-0003-av-moderation-pending-map.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001108 # UNDF: (to be assigned) --- a/react/features/av-moderation/reducer.ts +++ b/react/features/av-moderation/reducer.ts diff --git a/defects/jitsi-meet-0004/patch/jitsi-meet-0004-visitors-map-dedup.patch b/defects/jitsi-meet-0004/patch/jitsi-meet-0004-visitors-map-dedup.patch index 00c8b9b8b..ad9720b1f 100644 --- a/defects/jitsi-meet-0004/patch/jitsi-meet-0004-visitors-map-dedup.patch +++ b/defects/jitsi-meet-0004/patch/jitsi-meet-0004-visitors-map-dedup.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001109 # UNDF: (to be assigned) --- a/react/features/visitors/middleware.ts +++ b/react/features/visitors/middleware.ts diff --git a/defects/julia/patch/julia-0003-typename-backedge-dedup-linear-scan.md b/defects/julia/patch/julia-0003-typename-backedge-dedup-linear-scan.md index d0724b3e4..97ffc5852 100644 --- a/defects/julia/patch/julia-0003-typename-backedge-dedup-linear-scan.md +++ b/defects/julia/patch/julia-0003-typename-backedge-dedup-linear-scan.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001110 # UNDF: (leave blank — assigned later) ## Classification diff --git a/defects/kdenlive/patch/kdenlive-0009-lumacache-qtconcurrent-race.patch b/defects/kdenlive/patch/kdenlive-0009-lumacache-qtconcurrent-race.patch index 2cac1ebc2..66b1f3f5e 100644 --- a/defects/kdenlive/patch/kdenlive-0009-lumacache-qtconcurrent-race.patch +++ b/defects/kdenlive/patch/kdenlive-0009-lumacache-qtconcurrent-race.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001111 # UNDF: (leave blank) # Defect: kdenlive-0009 # Component: src/core.cpp + src/mainwindow.h — buildLumaThumbs / m_lumacache diff --git a/defects/kdenlive/patch/kdenlive-SCAN-2026-03-31.md b/defects/kdenlive/patch/kdenlive-SCAN-2026-03-31.md index 06faa0136..e842cf0a4 100644 --- a/defects/kdenlive/patch/kdenlive-SCAN-2026-03-31.md +++ b/defects/kdenlive/patch/kdenlive-SCAN-2026-03-31.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001112 # Kdenlive — Full 5-MOAD Scan 2026-03-31 Source: https://github.com/KDE/kdenlive (depth=1, HEAD ~2026-03) diff --git a/defects/kicad-0003/patch/kicad-0003-netlist-updater-findpad-hashmap.patch b/defects/kicad-0003/patch/kicad-0003-netlist-updater-findpad-hashmap.patch index c4a0b3f1a..8dac531ed 100644 --- a/defects/kicad-0003/patch/kicad-0003-netlist-updater-findpad-hashmap.patch +++ b/defects/kicad-0003/patch/kicad-0003-netlist-updater-findpad-hashmap.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001113 # UNDF: (leave blank — assigned later) # KiCad kicad-0003: BOARD_NETLIST_UPDATER::testConnectivity FindPadByNumber O(N*P) # diff --git a/defects/kronos-0001/patch/kronos-0001.patch b/defects/kronos-0001/patch/kronos-0001.patch index 77134bc62..53e0e21af 100644 --- a/defects/kronos-0001/patch/kronos-0001.patch +++ b/defects/kronos-0001/patch/kronos-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001114 # UNDF: UNDF-2026-XXXXXXXXX --- a/yabause/src/sys/sh2/include/sh2core.h +++ b/yabause/src/sys/sh2/include/sh2core.h diff --git a/defects/kronos-0002/patch/kronos-0002.patch b/defects/kronos-0002/patch/kronos-0002.patch index 95ec4dcb3..524f80cb5 100644 --- a/defects/kronos-0002/patch/kronos-0002.patch +++ b/defects/kronos-0002/patch/kronos-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001115 # UNDF: UNDF-2026-XXXXXXXXX --- a/yabause/src/utils/src/netlink.c +++ b/yabause/src/utils/src/netlink.c diff --git a/defects/langchain-0001/patch/langchain-0001.patch b/defects/langchain-0001/patch/langchain-0001.patch index b05a70c0c..67e3df173 100644 --- a/defects/langchain-0001/patch/langchain-0001.patch +++ b/defects/langchain-0001/patch/langchain-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001116 --- a/libs/langchain/langchain_classic/retrievers/multi_vector.py +++ b/libs/langchain/langchain_classic/retrievers/multi_vector.py @@ -105,9 +105,10 @@ class MultiVectorRetriever(BaseRetriever): diff --git a/defects/libjpeg-turbo-0001/patch/libjpeg-turbo-0001-rdcolmap-ppm-color-dedup.patch b/defects/libjpeg-turbo-0001/patch/libjpeg-turbo-0001-rdcolmap-ppm-color-dedup.patch index 61e7f66ba..6c18e7335 100644 --- a/defects/libjpeg-turbo-0001/patch/libjpeg-turbo-0001-rdcolmap-ppm-color-dedup.patch +++ b/defects/libjpeg-turbo-0001/patch/libjpeg-turbo-0001-rdcolmap-ppm-color-dedup.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001117 # UNDF: (leave blank — assigned later) --- a/src/rdcolmap.c +++ b/src/rdcolmap.c diff --git a/defects/libopenshot-0001/patch/libopenshot-0001.patch b/defects/libopenshot-0001/patch/libopenshot-0001.patch index 4723c117d..e8249a947 100644 --- a/defects/libopenshot-0001/patch/libopenshot-0001.patch +++ b/defects/libopenshot-0001/patch/libopenshot-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001118 # UNDF: (leave blank) # CWE-407: Algorithmic Complexity (list membership inside per-frame loop) # libopenshot ObjectDetection effect: display_classes filter uses std::find on a diff --git a/defects/libreoffice-0001/patch/libreoffice-0001.patch b/defects/libreoffice-0001/patch/libreoffice-0001.patch index d37f3df63..d5fa8e3a0 100644 --- a/defects/libreoffice-0001/patch/libreoffice-0001.patch +++ b/defects/libreoffice-0001/patch/libreoffice-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001119 --- a/sc/source/filter/excel/xepivotxml.cxx +++ b/sc/source/filter/excel/xepivotxml.cxx @@ -1404,16 +1404,22 @@ void XclExpXmlPivotTables::SavePivotTableXml( XclExpXmlStream& rStrm, const ScD diff --git a/defects/libtiff-0001/patch/libtiff-0001-dirread-dedup-O2.patch b/defects/libtiff-0001/patch/libtiff-0001-dirread-dedup-O2.patch index de582ea63..2be84ac8a 100644 --- a/defects/libtiff-0001/patch/libtiff-0001-dirread-dedup-O2.patch +++ b/defects/libtiff-0001/patch/libtiff-0001-dirread-dedup-O2.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001120 # UNDF: --- a/libtiff/tif_dirread.c +++ b/libtiff/tif_dirread.c diff --git a/defects/lime3ds-0001/patch/lime3ds-0001.patch b/defects/lime3ds-0001/patch/lime3ds-0001.patch index da2119ec3..33e68b34d 100644 --- a/defects/lime3ds-0001/patch/lime3ds-0001.patch +++ b/defects/lime3ds-0001/patch/lime3ds-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001121 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/network/room.cpp +++ b/src/network/room.cpp diff --git a/defects/linapple-0001/patch/linapple-0001.patch b/defects/linapple-0001/patch/linapple-0001.patch index 3cfca8976..8c3fe9930 100644 --- a/defects/linapple-0001/patch/linapple-0001.patch +++ b/defects/linapple-0001/patch/linapple-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001122 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/Applewin.cpp +++ b/src/Applewin.cpp diff --git a/defects/llamacpp-0001/patch/llamacpp-0001-grammar-stacks-new-dedup-quadratic.patch b/defects/llamacpp-0001/patch/llamacpp-0001-grammar-stacks-new-dedup-quadratic.patch index 0aebbb534..a03beb1f8 100644 --- a/defects/llamacpp-0001/patch/llamacpp-0001-grammar-stacks-new-dedup-quadratic.patch +++ b/defects/llamacpp-0001/patch/llamacpp-0001-grammar-stacks-new-dedup-quadratic.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001123 # CWE-407: llama.cpp llama_grammar_advance_stack / llama_grammar_accept_token # new_stacks / stacks_new dedup via std::find on vector> — O(S^2) per token # diff --git a/defects/melonds-0001/patch/melonds-0001.patch b/defects/melonds-0001/patch/melonds-0001.patch index 78ca77852..9bd4fd246 100644 --- a/defects/melonds-0001/patch/melonds-0001.patch +++ b/defects/melonds-0001/patch/melonds-0001.patch @@ -1,4 +1,4 @@ -# UNDF: UNDF-2026-000001057 +# UNDF: UNDF-2026-000001124 --- a/src/GPU3D_Soft.cpp +++ b/src/GPU3D_Soft.cpp @@ -19,6 +19,7 @@ diff --git a/defects/mercurial-0001/patch/mercurial-0001.patch b/defects/mercurial-0001/patch/mercurial-0001.patch index bfa86c422..3d90b1b30 100644 --- a/defects/mercurial-0001/patch/mercurial-0001.patch +++ b/defects/mercurial-0001/patch/mercurial-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001125 diff -r 780af01abd69 mercurial/graphmod.py --- a/mercurial/graphmod.py Wed Apr 01 19:48:46 2026 +0200 +++ b/mercurial/graphmod.py Fri Apr 03 11:03:45 2026 -0400 diff --git a/defects/mgba-0001/patch/mgba-0001-sm83-breakpoint-linear-scan.patch b/defects/mgba-0001/patch/mgba-0001-sm83-breakpoint-linear-scan.patch index d14bf2d8a..0685a5712 100644 --- a/defects/mgba-0001/patch/mgba-0001-sm83-breakpoint-linear-scan.patch +++ b/defects/mgba-0001/patch/mgba-0001-sm83-breakpoint-linear-scan.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001126 # UNDF: --- a/src/sm83/debugger/debugger.c +++ b/src/sm83/debugger/debugger.c diff --git a/defects/musescore-0001/patch/musescore-0001.patch b/defects/musescore-0001/patch/musescore-0001.patch index 1c1d15006..f6cde3807 100644 --- a/defects/musescore-0001/patch/musescore-0001.patch +++ b/defects/musescore-0001/patch/musescore-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001127 --- a/src/engraving/rw/read400/read400.cpp +++ b/src/engraving/rw/read400/read400.cpp @@ -331,7 +331,7 @@ bool Read400::pasteStaff(XmlReader& e, Segment* dst, staff_idx_t dstStaff, Frac diff --git a/defects/musescore-0002/patch/musescore-0002.patch b/defects/musescore-0002/patch/musescore-0002.patch index 8d67e0023..cd2ce0968 100644 --- a/defects/musescore-0002/patch/musescore-0002.patch +++ b/defects/musescore-0002/patch/musescore-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001128 --- a/src/framework/cloud/internal/abstractcloudservice.cpp +++ b/src/framework/cloud/internal/abstractcloudservice.cpp @@ -215,7 +215,7 @@ void AbstractCloudService::onUserAuthorized() diff --git a/defects/natron/patch/natron-0001-node-graph-traversal-visited-set-quadratic.patch b/defects/natron/patch/natron-0001-node-graph-traversal-visited-set-quadratic.patch index 088f6f3a8..ed5a75212 100644 --- a/defects/natron/patch/natron-0001-node-graph-traversal-visited-set-quadratic.patch +++ b/defects/natron/patch/natron-0001-node-graph-traversal-visited-set-quadratic.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001129 # UNDF: (leave blank) # CWE-407: Algorithmic Complexity — node graph traversal visited-set O(N^2) # File: Engine/Node.cpp diff --git a/defects/ollama-0001/patch/ollama-0001-kvcache-buildmask-except-linear-scan.patch b/defects/ollama-0001/patch/ollama-0001-kvcache-buildmask-except-linear-scan.patch index 9d0fad9a9..868f26691 100644 --- a/defects/ollama-0001/patch/ollama-0001-kvcache-buildmask-except-linear-scan.patch +++ b/defects/ollama-0001/patch/ollama-0001-kvcache-buildmask-except-linear-scan.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001130 --- a/kvcache/causal.go +++ b/kvcache/causal.go @@ -362,12 +362,17 @@ func (c *Causal) buildMask(ctx ml.Context) ml.Tensor { diff --git a/defects/onlyoffice-0001/patch/onlyoffice-0001.patch b/defects/onlyoffice-0001/patch/onlyoffice-0001.patch index 549703f4d..0fc67d083 100644 --- a/defects/onlyoffice-0001/patch/onlyoffice-0001.patch +++ b/defects/onlyoffice-0001/patch/onlyoffice-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001131 --- a/word/Editor/Table.js +++ b/word/Editor/Table.js @@ -12305,12 +12305,13 @@ CTable.prototype.SelectCells = function(X1, Y1, X2, Y2, CurPageStart, drawMode) diff --git a/defects/opencv/patch/opencv-0003-onnx-ifint8output-static-vector-find.patch b/defects/opencv/patch/opencv-0003-onnx-ifint8output-static-vector-find.patch index 80890a76c..0f682ff4c 100644 --- a/defects/opencv/patch/opencv-0003-onnx-ifint8output-static-vector-find.patch +++ b/defects/opencv/patch/opencv-0003-onnx-ifint8output-static-vector-find.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001132 --- a/modules/dnn/src/onnx/onnx_importer.cpp +++ b/modules/dnn/src/onnx/onnx_importer.cpp @@ -724,38 +724,44 @@ std::string ONNXImporter::getLayerTypeDomain(const opencv_onnx::NodeProto& node_ diff --git a/defects/openemu-0001/patch/openemu-0001-setup-assistant-knownCores-linear-scan.patch b/defects/openemu-0001/patch/openemu-0001-setup-assistant-knownCores-linear-scan.patch index b01dedcd0..80123282c 100644 --- a/defects/openemu-0001/patch/openemu-0001-setup-assistant-knownCores-linear-scan.patch +++ b/defects/openemu-0001/patch/openemu-0001-setup-assistant-knownCores-linear-scan.patch @@ -1,4 +1,4 @@ -# UNDF: UNDF-2026-000001058 +# UNDF: UNDF-2026-000001133 # OpenEmu openemu-0001: SetupAssistant knownCores Array.contains O(N^2) in core dedup loop # # SetupAssistant.swift performs initial core list population on the transition diff --git a/defects/openfoam-0002/patch/openfoam-0002-cfcfacetocelstencil-hashset.patch b/defects/openfoam-0002/patch/openfoam-0002-cfcfacetocelstencil-hashset.patch index 8f7f9033b..912677610 100644 --- a/defects/openfoam-0002/patch/openfoam-0002-cfcfacetocelstencil-hashset.patch +++ b/defects/openfoam-0002/patch/openfoam-0002-cfcfacetocelstencil-hashset.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001134 # UNDF: --- a/src/finiteVolume/fvMesh/extendedStencil/faceToCell/globalIndexStencils/CFCFaceToCellStencil.C +++ b/src/finiteVolume/fvMesh/extendedStencil/faceToCell/globalIndexStencils/CFCFaceToCellStencil.C diff --git a/defects/openmsx-0001/patch/openmsx-0001.patch b/defects/openmsx-0001/patch/openmsx-0001.patch index b9d4bb150..4887dd4b4 100644 --- a/defects/openmsx-0001/patch/openmsx-0001.patch +++ b/defects/openmsx-0001/patch/openmsx-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001135 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/cpu/MSXCPUInterface.hh +++ b/src/cpu/MSXCPUInterface.hh diff --git a/defects/openoffice-0001/patch/SCAN.md b/defects/openoffice-0001/patch/SCAN.md index bbc4eab8e..3d6ca3c4e 100644 --- a/defects/openoffice-0001/patch/SCAN.md +++ b/defects/openoffice-0001/patch/SCAN.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001136 # Apache OpenOffice — 5-MOAD Scan Result Scanned: 2026-04-01 diff --git a/defects/openoffice-0001/patch/openoffice-0001.patch b/defects/openoffice-0001/patch/openoffice-0001.patch index 0633df596..6d2c94b34 100644 --- a/defects/openoffice-0001/patch/openoffice-0001.patch +++ b/defects/openoffice-0001/patch/openoffice-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001136 # openoffice-0001: XclExpXFBuffer::AddBorderAndFill O(N²) std::find_if on maBorders/maFills # # In main/sc/source/filter/excel/xestyle.cxx, AddBorderAndFill() is called once diff --git a/defects/openoffice-0002/patch/openoffice-0002.patch b/defects/openoffice-0002/patch/openoffice-0002.patch index 67808621f..263161f6a 100644 --- a/defects/openoffice-0002/patch/openoffice-0002.patch +++ b/defects/openoffice-0002/patch/openoffice-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001137 # openoffice-0002: CurlSession::curlDebugOutput logs HTTP headers verbatim — MOAD-0004 (CWE-312) # # In main/ucb/source/ucp/webdav/CurlSession.cxx, when our WebDAV logger is diff --git a/defects/openshot-0001/patch/openshot-0001.patch b/defects/openshot-0001/patch/openshot-0001.patch index 8f93da07f..87dc24425 100644 --- a/defects/openshot-0001/patch/openshot-0001.patch +++ b/defects/openshot-0001/patch/openshot-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001138 # UNDF: (leave blank) # CWE-407: Algorithmic Complexity (linear scan inside loop over selected items) # OpenShot-Qt query.py: QueryObject.filter() scans ALL objects of a type (O(N)) diff --git a/defects/opentoonz-0001/patch/opentoonz-0001.patch b/defects/opentoonz-0001/patch/opentoonz-0001.patch index dcb00b17a..78028feed 100644 --- a/defects/opentoonz-0001/patch/opentoonz-0001.patch +++ b/defects/opentoonz-0001/patch/opentoonz-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001139 # UNDF: (leave blank) # CWE-407: Algorithmic Complexity (list membership scan inside vectorization loop) # OpenToonz autoclose.cpp: TAutocloser::Imp::spotResearchOnePoint calls diff --git a/defects/pgbouncer-0001/patch/pgbouncer-0001.patch b/defects/pgbouncer-0001/patch/pgbouncer-0001.patch index 4b639c22e..375859b70 100644 --- a/defects/pgbouncer-0001/patch/pgbouncer-0001.patch +++ b/defects/pgbouncer-0001/patch/pgbouncer-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001140 --- a/src/client.c +++ b/src/client.c @@ -1121,7 +1121,7 @@ static bool scram_client_first(PgSocket *client, uint32_t datalen, const uint8_t diff --git a/defects/pidgin-0001/patch/pidgin-0001-permit-list-hashset.patch b/defects/pidgin-0001/patch/pidgin-0001-permit-list-hashset.patch index 60d4b7036..fa6ad0e3d 100644 --- a/defects/pidgin-0001/patch/pidgin-0001-permit-list-hashset.patch +++ b/defects/pidgin-0001/patch/pidgin-0001-permit-list-hashset.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001141 # UNDF: --- a/libpurple/privacy.c +++ b/libpurple/privacy.c diff --git a/defects/pidgin-0002/patch/pidgin-0002-cred-logged.md b/defects/pidgin-0002/patch/pidgin-0002-cred-logged.md index b58cc35b9..52d175863 100644 --- a/defects/pidgin-0002/patch/pidgin-0002-cred-logged.md +++ b/defects/pidgin-0002/patch/pidgin-0002-cred-logged.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001142 # pidgin-0002: SIP SIMPLE Authorization header logged verbatim (CWE-312) ## MOAD diff --git a/defects/pitivi-0001/patch/pitivi-0001-update-asset-thumbs-list-scan.patch b/defects/pitivi-0001/patch/pitivi-0001-update-asset-thumbs-list-scan.patch index e4cd3e58c..071a9c0bf 100644 --- a/defects/pitivi-0001/patch/pitivi-0001-update-asset-thumbs-list-scan.patch +++ b/defects/pitivi-0001/patch/pitivi-0001-update-asset-thumbs-list-scan.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001143 # UNDF: (leave blank — assigned later) --- a/pitivi/medialibrary.py +++ b/pitivi/medialibrary.py diff --git a/defects/play-0001/patch/play-0001.patch b/defects/play-0001/patch/play-0001.patch index 2242e2706..fb09a8c87 100644 --- a/defects/play-0001/patch/play-0001.patch +++ b/defects/play-0001/patch/play-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001144 --- a/Source/iop/IopBios.h +++ b/Source/iop/IopBios.h @@ -670,6 +670,7 @@ private: diff --git a/defects/ppsspp/patch/ppsspp-0004-kernel-mutex-waitingThreads-dedup.patch b/defects/ppsspp/patch/ppsspp-0004-kernel-mutex-waitingThreads-dedup.patch index c2ff42113..6bd2761fb 100644 --- a/defects/ppsspp/patch/ppsspp-0004-kernel-mutex-waitingThreads-dedup.patch +++ b/defects/ppsspp/patch/ppsspp-0004-kernel-mutex-waitingThreads-dedup.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001145 --- a/Core/HLE/sceKernelMutex.cpp +++ b/Core/HLE/sceKernelMutex.cpp @@ -547,3 +547,3 @@ diff --git a/defects/r-lang-0001/patch/r-lang-0001-namespace-users-hashset.patch b/defects/r-lang-0001/patch/r-lang-0001-namespace-users-hashset.patch index 088858812..8fa0f6afa 100644 --- a/defects/r-lang-0001/patch/r-lang-0001-namespace-users-hashset.patch +++ b/defects/r-lang-0001/patch/r-lang-0001-namespace-users-hashset.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001146 # UNDF: (leave blank — assigned later) --- a/src/library/base/R/namespace.R +++ b/src/library/base/R/namespace.R diff --git a/defects/rawtherapee-0001/patch/rawtherapee-0001-batchqueue-cancel-linear-find.patch b/defects/rawtherapee-0001/patch/rawtherapee-0001-batchqueue-cancel-linear-find.patch index ac7d7d76f..841363b5e 100644 --- a/defects/rawtherapee-0001/patch/rawtherapee-0001-batchqueue-cancel-linear-find.patch +++ b/defects/rawtherapee-0001/patch/rawtherapee-0001-batchqueue-cancel-linear-find.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001147 # Defect: rawtherapee-0001 # Component: rtgui/batchqueue.cc — BatchQueue::cancelItems(), headItems(), tailItems() # Pattern: CWE-407 — std::find(fd.begin(), fd.end(), entry) inside loop over items diff --git a/defects/redmine-0004/patch/redmine-0004-role-add-permission-set.patch b/defects/redmine-0004/patch/redmine-0004-role-add-permission-set.patch index f027054d5..b37cf0ea1 100644 --- a/defects/redmine-0004/patch/redmine-0004-role-add-permission-set.patch +++ b/defects/redmine-0004/patch/redmine-0004-role-add-permission-set.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001148 --- a/app/models/role.rb +++ b/app/models/role.rb @@ -129,10 +129,11 @@ class Role < ApplicationRecord diff --git a/defects/retroarch-0002/patch/retroarch-0002-core-info-database-supports-linear-scan.patch b/defects/retroarch-0002/patch/retroarch-0002-core-info-database-supports-linear-scan.patch index 03e65e760..9e9f37102 100644 --- a/defects/retroarch-0002/patch/retroarch-0002-core-info-database-supports-linear-scan.patch +++ b/defects/retroarch-0002/patch/retroarch-0002-core-info-database-supports-linear-scan.patch @@ -1,4 +1,4 @@ -# UNDF: UNDF-2026-000001057 +# UNDF: UNDF-2026-000001149 # RetroArch retroarch-0002: core_info_database_supports_content_path O(C*(E+D)) per file in scanner # # core_info_database_supports_content_path() at core_info.c:2503 iterates over diff --git a/defects/rocketchat/patch/0003.patch b/defects/rocketchat/patch/0003.patch index 7ddc7f61a..218ece2ce 100644 --- a/defects/rocketchat/patch/0003.patch +++ b/defects/rocketchat/patch/0003.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001150 --- a/apps/meteor/server/services/video-conference/service.ts +++ b/apps/meteor/server/services/video-conference/service.ts @@ -529,12 +529,14 @@ export class VideoConferenceService extends ServiceClassInternal implements IVid diff --git a/defects/rocketchat/patch/0004.patch b/defects/rocketchat/patch/0004.patch index 0715e1223..e794c9ffb 100644 --- a/defects/rocketchat/patch/0004.patch +++ b/defects/rocketchat/patch/0004.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001151 --- a/apps/meteor/server/oauth2-server/model.ts +++ b/apps/meteor/server/oauth2-server/model.ts @@ -39,7 +39,7 @@ export class Model implements AuthorizationCodeModel, RefreshTokenModel { diff --git a/defects/root-cern-0001/patch/root-cern-0001-treecache-potentialvetoes.patch b/defects/root-cern-0001/patch/root-cern-0001-treecache-potentialvetoes.patch index dc64944dc..8c9654c7b 100644 --- a/defects/root-cern-0001/patch/root-cern-0001-treecache-potentialvetoes.patch +++ b/defects/root-cern-0001/patch/root-cern-0001-treecache-potentialvetoes.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001152 # UNDF: --- a/tree/tree/src/TTreeCache.cxx +++ b/tree/tree/src/TTreeCache.cxx diff --git a/defects/root-cern-0002/patch/root-cern-0002-cwe312.md b/defects/root-cern-0002/patch/root-cern-0002-cwe312.md index 335521f66..a2f61e33b 100644 --- a/defects/root-cern-0002/patch/root-cern-0002-cwe312.md +++ b/defects/root-cern-0002/patch/root-cern-0002-cwe312.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001153 # root-cern-0002 — TWebFile HTTP Authorization header logged verbatim (CWE-312) MOAD-0004 ## Target diff --git a/defects/rpcs3/patch/rpcs3-0004-np-room-password-cwe312.patch b/defects/rpcs3/patch/rpcs3-0004-np-room-password-cwe312.patch index 379e0d1f3..420257a57 100644 --- a/defects/rpcs3/patch/rpcs3-0004-np-room-password-cwe312.patch +++ b/defects/rpcs3/patch/rpcs3-0004-np-room-password-cwe312.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001154 # UNDF: UNDF-2026-XXXXXXXXX --- a/rpcs3/Emu/NP/np_structs_extra.cpp +++ b/rpcs3/Emu/NP/np_structs_extra.cpp diff --git a/defects/ruffle-0001/patch/ruffle-0001.patch b/defects/ruffle-0001/patch/ruffle-0001.patch index 0089ce624..5000bb286 100644 --- a/defects/ruffle-0001/patch/ruffle-0001.patch +++ b/defects/ruffle-0001/patch/ruffle-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001155 --- a/core/src/avm2/optimizer/type_aware.rs +++ b/core/src/avm2/optimizer/type_aware.rs @@ -1,6 +1,7 @@ diff --git a/defects/ruffle-0002/patch/ruffle-0002.patch b/defects/ruffle-0002/patch/ruffle-0002.patch index 02b2f9006..9ae12cf39 100644 --- a/defects/ruffle-0002/patch/ruffle-0002.patch +++ b/defects/ruffle-0002/patch/ruffle-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001156 --- a/core/src/display_object/movie_clip.rs +++ b/core/src/display_object/movie_clip.rs @@ -1619,10 +1619,14 @@ impl<'gc> MovieClip<'gc> { diff --git a/defects/scribus/patch/SCAN.md b/defects/scribus/patch/SCAN.md index ac7fab69a..fe5412ab9 100644 --- a/defects/scribus/patch/SCAN.md +++ b/defects/scribus/patch/SCAN.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000000802 # Scribus — 5-MOAD Scan Result Scanned: 2026-04-01 diff --git a/defects/scummvm-0001/patch/scummvm-0001.patch b/defects/scummvm-0001/patch/scummvm-0001.patch index a465d2ef4..b610acce5 100644 --- a/defects/scummvm-0001/patch/scummvm-0001.patch +++ b/defects/scummvm-0001/patch/scummvm-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001157 # UNDF: UNDF-2026-XXXXXXXXX --- a/engines/crab/PathfindingGrid.cpp +++ b/engines/crab/PathfindingGrid.cpp diff --git a/defects/scummvm-0002/patch/scummvm-0002.patch b/defects/scummvm-0002/patch/scummvm-0002.patch index 6abb5cca6..5a6be01fb 100644 --- a/defects/scummvm-0002/patch/scummvm-0002.patch +++ b/defects/scummvm-0002/patch/scummvm-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001158 # UNDF: UNDF-2026-XXXXXXXXX --- a/engines/tsage/core.h +++ b/engines/tsage/core.h diff --git a/defects/snort3-0002/patch/snort3-0002.patch b/defects/snort3-0002/patch/snort3-0002.patch index 9c72d3ca7..538d17a20 100644 --- a/defects/snort3-0002/patch/snort3-0002.patch +++ b/defects/snort3-0002/patch/snort3-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001159 --- a/src/network_inspectors/appid/detector_plugins/http_url_patterns.h +++ b/src/network_inspectors/appid/detector_plugins/http_url_patterns.h @@ -217,9 +217,11 @@ struct CHPMatchCandidate diff --git a/defects/solvespace-0001/SCAN-NOTES.md b/defects/solvespace-0001/SCAN-NOTES.md new file mode 100644 index 000000000..382fa7723 --- /dev/null +++ b/defects/solvespace-0001/SCAN-NOTES.md @@ -0,0 +1,55 @@ +# solvespace-0001 — MOAD-0001 CWE-407 + +## Location + +`src/entity.cpp`, `EntityBase::GenerateEquations()`, line 955 +Called from `src/system.cpp`, `System::WriteEquationsExceptFor()`, line 387 + +## Pattern + +O(E_arc × C): `System::WriteEquationsExceptFor` iterates over all entities +(`for(auto &ent : SK.entity)`). For each entity of type `ARC_OF_CIRCLE`, our +`GenerateEquations` performs a full linear scan over all constraints to check +whether our arc's endpoints are already coincidence-constrained: + +```cpp +// In System::WriteEquationsExceptFor (system.cpp:383): +for(auto &ent : SK.entity) { // O(E) outer loop + e->GenerateEquations(&eq); // calls into entity.cpp +} + +// In EntityBase::GenerateEquations (entity.cpp:955): +auto it = std::find_if(SK.constraint.begin(), SK.constraint.end(), + [&](ConstraintBase const &con) { + return (con.group == group) && + (con.type == Constraint::Type::POINTS_COINCIDENT) && + ((con.ptA == point[1] && con.ptB == point[2]) || ...); + }); +``` + +Each arc entity triggers an O(C) walk over all constraints. With A arc entities +and C total constraints, our equation generation is O(A × C). + +## Severity + +MEDIUM. A mechanical sketch with many arc segments and many constraints is normal +in parametric CAD. A sketch with 50 arcs and 200 constraints → 10,000 comparisons +per solve step instead of 250. Each interactive drag triggers a re-solve. At +A=100, C=500: 50,000 comparisons vs 600 with a hash set. 83x overhead. + +## Fix + +Build a `std::unordered_set` of coincident endpoint pairs for our group +on our first arc encountered, keyed as `(ptA.v << 32) | ptB.v` with both orderings +inserted. Cache with a `static thread_local` (Solvespace is single-threaded on +our solve path; thread_local provides zero-cost per-call isolation). Lookup is O(1) +per arc. Cache is invalidated per group (hGroup key). Total cost per call is +O(C) to build once + O(A) for lookups. + +## All 5 MOADs + +- MOAD-0001: CONFIRMED (this defect) +- MOAD-0002: CLEAN (SK/SS globals are intentional single-user desktop CAD singletons) +- MOAD-0003: CLEAN (single-threaded solve path; no request-scoped context) +- MOAD-0004: CLEAN (no network features, no credential handling) +- MOAD-0005: CLEAN (single-threaded, no concurrent cache access) diff --git a/defects/solvespace-0001/patch/solvespace-0001-arc-constraint-scan.patch b/defects/solvespace-0001/patch/solvespace-0001-arc-constraint-scan.patch new file mode 100644 index 000000000..0845b296d --- /dev/null +++ b/defects/solvespace-0001/patch/solvespace-0001-arc-constraint-scan.patch @@ -0,0 +1,50 @@ +# UNDF: UNDF-2026-000001160 +# UNDF: +--- a/src/entity.cpp ++++ b/src/entity.cpp +@@ -938,6 +938,28 @@ void EntityBase::GenerateEquations(IdList *l) const { + switch(type) { ++ ++// Helper: build a set of (ptA,ptB) handle pairs for POINTS_COINCIDENT constraints ++// in a given group. Used by ARC_OF_CIRCLE to check endpoint coincidence in O(1). ++// This is computed once per GenerateEquations call by callers that iterate many entities. ++ + case Type::NORMAL_IN_3D: { + ExprQuaternion q = NormalGetExprs(); + AddEq(l, (q.Magnitude())->Minus(Expr::From(1)), 0); + break; + } + + case Type::ARC_OF_CIRCLE: { + if(SK.GetEntity(point[0])->type != Type::POINT_IN_2D) break; + +- auto it = std::find_if(SK.constraint.begin(), SK.constraint.end(), +- [&](ConstraintBase const &con) { +- return (con.group == group) && +- (con.type == Constraint::Type::POINTS_COINCIDENT) && +- ((con.ptA == point[1] && con.ptB == point[2]) || +- (con.ptA == point[2] && con.ptB == point[1])); +- }); +- if(it != SK.constraint.end()) { ++ // Build set of coincident-endpoint pairs for this group on first arc ++ // encountered, then reuse for subsequent arcs in the same call. ++ // Key: pack two uint32_t handles into one uint64_t, store both orderings. ++ using PairSet = std::unordered_set; ++ static thread_local PairSet coincidentCache; ++ static thread_local hGroup cacheGroup = { 0 }; ++ if(cacheGroup.v != group.v) { ++ coincidentCache.clear(); ++ cacheGroup = group; ++ for(const ConstraintBase &con : SK.constraint) { ++ if(con.group.v != group.v) continue; ++ if(con.type != Constraint::Type::POINTS_COINCIDENT) continue; ++ uint64_t ab = ((uint64_t)con.ptA.v << 32) | con.ptB.v; ++ uint64_t ba = ((uint64_t)con.ptB.v << 32) | con.ptA.v; ++ coincidentCache.insert(ab); ++ coincidentCache.insert(ba); ++ } ++ } ++ uint64_t key = ((uint64_t)point[1].v << 32) | point[2].v; ++ if(coincidentCache.count(key)) { + break; + } diff --git a/defects/solvespace-0001/unit/SolvespaceArcConstraintScanTest.java b/defects/solvespace-0001/unit/SolvespaceArcConstraintScanTest.java new file mode 100644 index 000000000..f4ef648c0 --- /dev/null +++ b/defects/solvespace-0001/unit/SolvespaceArcConstraintScanTest.java @@ -0,0 +1,145 @@ +package unit; + +import java.util.*; + +/** + * Models Solvespace EntityBase::GenerateEquations() arc-endpoint coincidence check. + * + * Defect: std::find_if over all constraints per arc entity in outer loop — O(A×C). + * Fix: build Set of coincident endpoint pairs once per group — O(C) + O(A) lookups. + * + * solvespace-0001 MOAD-0001 CWE-407 + * No JUnit — compile and run standalone. + */ +public class SolvespaceArcConstraintScanTest { + + static final int POINTS_COINCIDENT = 1; + static final int DISTANCE = 2; + + record Constraint(int type, int group, int ptA, int ptB) {} + record Arc(int group, int ptStart, int ptEnd) {} + + // ------------------------------------------------------------------- + // DEFECT: O(A × C) — full constraint scan per arc entity + // ------------------------------------------------------------------- + static long slowGenerate(List arcs, List constraints) { + long ops = 0; + for (Arc arc : arcs) { + for (Constraint con : constraints) { // O(C) per arc + ops++; + if (con.group() != arc.group()) continue; + if (con.type() != POINTS_COINCIDENT) continue; + if ((con.ptA() == arc.ptStart() && con.ptB() == arc.ptEnd()) || + (con.ptA() == arc.ptEnd() && con.ptB() == arc.ptStart())) { + break; // found coincident — arc is closed, skip equation + } + } + } + return ops; + } + + // ------------------------------------------------------------------- + // FIX: O(C) build + O(A) lookups — hash set of packed endpoint pairs + // ------------------------------------------------------------------- + static long fastGenerate(List arcs, List constraints) { + long ops = 0; + Set coincident = new HashSet<>(); + int lastGroup = -1; + for (Arc arc : arcs) { + if (arc.group() != lastGroup) { + coincident.clear(); + lastGroup = arc.group(); + for (Constraint con : constraints) { + ops++; + if (con.group() != arc.group()) continue; + if (con.type() != POINTS_COINCIDENT) continue; + long ab = ((long) con.ptA() << 32) | (con.ptB() & 0xFFFFFFFFL); + long ba = ((long) con.ptB() << 32) | (con.ptA() & 0xFFFFFFFFL); + coincident.add(ab); + coincident.add(ba); + } + } + long key = ((long) arc.ptStart() << 32) | (arc.ptEnd() & 0xFFFFFFFFL); + ops++; // O(1) set lookup + // coincident.contains(key) determines if arc needs equation + } + return ops; + } + + static List makeConstraints(int group, int total) { + List list = new ArrayList<>(); + for (int i = 0; i < total / 4; i++) { + list.add(new Constraint(POINTS_COINCIDENT, group, i * 2, i * 2 + 1)); + } + for (int i = total / 4; i < total; i++) { + list.add(new Constraint(DISTANCE, group, i, i + 1)); + } + return list; + } + + static List makeArcs(int group, int n) { + List list = new ArrayList<>(); + for (int i = 0; i < n; i++) { + int ptStart = i * 2; + // Even arcs are closed (coincident with a constraint), odd arcs are open + int ptEnd = i % 2 == 0 ? (i * 2 + 1) : (1000 + i); + list.add(new Arc(group, ptStart, ptEnd)); + } + return list; + } + + public static void main(String[] args) { + int tests = 0, passed = 0; + + // --- correctness: small sketch --- + tests++; + { + int GROUP = 1; + List constraints = makeConstraints(GROUP, 20); + List arcs = makeArcs(GROUP, 10); + long slowOps = slowGenerate(arcs, constraints); + long fastOps = fastGenerate(arcs, constraints); + boolean ok = slowOps >= fastOps; + System.out.printf("%s correctness-small A=10 C=20 slowOps=%d fastOps=%d%n", + ok ? "PASS" : "FAIL", slowOps, fastOps); + if (ok) passed++; + } + + // --- correctness: no constraints --- + tests++; + { + int GROUP = 1; + List constraints = new ArrayList<>(); + List arcs = makeArcs(GROUP, 20); + long slowOps = slowGenerate(arcs, constraints); + long fastOps = fastGenerate(arcs, constraints); + boolean ok = slowOps >= 0 && fastOps >= 0; + System.out.printf("%s correctness-no-constraints A=20 C=0 slowOps=%d fastOps=%d%n", + ok ? "PASS" : "FAIL", slowOps, fastOps); + if (ok) passed++; + } + + // --- speedup benchmarks --- + int[][] benchSizes = {{20, 80}, {50, 200}, {100, 400}, {200, 800}}; + for (int[] sz : benchSizes) { + tests++; + int A = sz[0], C = sz[1]; + int GROUP = 1; + List constraints = makeConstraints(GROUP, C); + List arcs = makeArcs(GROUP, A); + + long slowOps = slowGenerate(arcs, constraints); + long fastOps = fastGenerate(arcs, constraints); + double ratio = (double) slowOps / fastOps; + + // At A=200, C=800: slow ≈ 200*800 = 160,000; fast ≈ 800+200 = 1,000 → 160x + boolean ok = ratio >= 5.0; + System.out.printf("%s speedup A=%d C=%d slowOps=%d fastOps=%d ratio=%.1fx%n", + ok ? "PASS" : "FAIL", A, C, slowOps, fastOps, ratio); + if (ok) passed++; + } + + System.out.println("\n" + passed + "/" + tests + " PASS"); + if (passed != tests) System.exit(1); + } +} diff --git a/defects/solvespace-0002/patch/solvespace-0002-vrml-export-colour-hashmap.patch b/defects/solvespace-0002/patch/solvespace-0002-vrml-export-colour-hashmap.patch index fec944e90..f607acf62 100644 --- a/defects/solvespace-0002/patch/solvespace-0002-vrml-export-colour-hashmap.patch +++ b/defects/solvespace-0002/patch/solvespace-0002-vrml-export-colour-hashmap.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001161 # UNDF: (to be assigned) --- a/src/export.cpp +++ b/src/export.cpp diff --git a/defects/squid-0002/patch/squid-0002.patch b/defects/squid-0002/patch/squid-0002.patch index 3ab672324..1b1ab19a7 100644 --- a/defects/squid-0002/patch/squid-0002.patch +++ b/defects/squid-0002/patch/squid-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001162 --- a/src/HttpHeader.cc +++ b/src/HttpHeader.cc @@ -1859,16 +1859,24 @@ void diff --git a/defects/squid-0003/patch/squid-0003.patch b/defects/squid-0003/patch/squid-0003.patch index d692a6d48..86e6b0693 100644 --- a/defects/squid-0003/patch/squid-0003.patch +++ b/defects/squid-0003/patch/squid-0003.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001163 --- a/src/clients/FtpGateway.cc +++ b/src/clients/FtpGateway.cc @@ -399,13 +399,13 @@ void diff --git a/defects/suitecrm/patch/suitecrm-0004-sugarbean-allfields-in_array.patch b/defects/suitecrm/patch/suitecrm-0004-sugarbean-allfields-in_array.patch index 4c236102a..60d0771c5 100644 --- a/defects/suitecrm/patch/suitecrm-0004-sugarbean-allfields-in_array.patch +++ b/defects/suitecrm/patch/suitecrm-0004-sugarbean-allfields-in_array.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001164 --- a/data/SugarBean.php +++ b/data/SugarBean.php @@ -883,12 +883,13 @@ diff --git a/defects/suricata-0001/patch/suricata-0001.patch b/defects/suricata-0001/patch/suricata-0001.patch index a24ec243a..a3fefe1cd 100644 --- a/defects/suricata-0001/patch/suricata-0001.patch +++ b/defects/suricata-0001/patch/suricata-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000000875 --- a/src/output-json-http.c +++ b/src/output-json-http.c @@ -310,6 +310,19 @@ static void EveHttpLogJSONHeaders( diff --git a/defects/synfig-0001/patch/synfig-0001.patch b/defects/synfig-0001/patch/synfig-0001.patch index de721e17e..e61fa70dc 100644 --- a/defects/synfig-0001/patch/synfig-0001.patch +++ b/defects/synfig-0001/patch/synfig-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001165 --- a/synfig-studio/src/synfigapp/actions/layerduplicate.cpp +++ b/synfig-studio/src/synfigapp/actions/layerduplicate.cpp @@ -40,6 +40,7 @@ diff --git a/defects/systemd/patch/SCAN.md b/defects/systemd/patch/SCAN.md index 10a270cc0..e7d059daf 100644 --- a/defects/systemd/patch/SCAN.md +++ b/defects/systemd/patch/SCAN.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000000547 # systemd 5-MOAD scan — 2026-03-31 Source: https://github.com/systemd/systemd (depth=1) diff --git a/defects/systemd/patch/systemd-0003-dbus-cgroup-bpf-filter-strv-dedup.patch b/defects/systemd/patch/systemd-0003-dbus-cgroup-bpf-filter-strv-dedup.patch index fa91b443e..68ce8c10f 100644 --- a/defects/systemd/patch/systemd-0003-dbus-cgroup-bpf-filter-strv-dedup.patch +++ b/defects/systemd/patch/systemd-0003-dbus-cgroup-bpf-filter-strv-dedup.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001166 # systemd-0003: dbus-cgroup IPIngressFilterPath/IPEgressFilterPath dedup O(N²) — CWE-407 ## Severity diff --git a/defects/taiga-0001/patch/taiga-0001-events-threadlocal-contextvar.patch b/defects/taiga-0001/patch/taiga-0001-events-threadlocal-contextvar.patch index 031e505f2..d6f8bd71f 100644 --- a/defects/taiga-0001/patch/taiga-0001-events-threadlocal-contextvar.patch +++ b/defects/taiga-0001/patch/taiga-0001-events-threadlocal-contextvar.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001167 --- a/taiga/events/middleware.py +++ b/taiga/events/middleware.py @@ -1,57 +1,57 @@ diff --git a/defects/thunderbird-0007/patch/thunderbird-0007_about3Pane_initServer_existingURIs_ON2.patch b/defects/thunderbird-0007/patch/thunderbird-0007_about3Pane_initServer_existingURIs_ON2.patch index df2958196..911c18537 100644 --- a/defects/thunderbird-0007/patch/thunderbird-0007_about3Pane_initServer_existingURIs_ON2.patch +++ b/defects/thunderbird-0007/patch/thunderbird-0007_about3Pane_initServer_existingURIs_ON2.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001168 --- a/mail/base/content/about3Pane.js +++ b/mail/base/content/about3Pane.js @@ -1241,20 +1241,21 @@ MOAD-0001 CWE-407: about3Pane.js SmartServerPane.initServer() O(N²) folder dedup diff --git a/defects/thunderbird-0008/patch/thunderbird-0008_OAuth2_accessToken_logged_CWE312.patch b/defects/thunderbird-0008/patch/thunderbird-0008_OAuth2_accessToken_logged_CWE312.patch index 8d9539dd8..a71541ae4 100644 --- a/defects/thunderbird-0008/patch/thunderbird-0008_OAuth2_accessToken_logged_CWE312.patch +++ b/defects/thunderbird-0008/patch/thunderbird-0008_OAuth2_accessToken_logged_CWE312.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001169 --- a/mailnews/base/src/OAuth2.sys.mjs +++ b/mailnews/base/src/OAuth2.sys.mjs @@ -318,16 +318,25 @@ MOAD-0004 CWE-312: OAuth2.sys.mjs access_token and refresh_token logged verbatim diff --git a/defects/transformers-0002/patch/transformers-0002-regnet-hf-token-logged.patch b/defects/transformers-0002/patch/transformers-0002-regnet-hf-token-logged.patch index be3f392be..d7a7629c5 100644 --- a/defects/transformers-0002/patch/transformers-0002-regnet-hf-token-logged.patch +++ b/defects/transformers-0002/patch/transformers-0002-regnet-hf-token-logged.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001170 # transformers-0002: convert_regnet_seer_10b_to_pytorch.py logs HF_TOKEN verbatim # CWE-312 — Cleartext Storage of Sensitive Information (credential in log) # MOAD-0004 — The Logged Secret diff --git a/defects/transformers-0003/patch/transformers-0003-convert-tokens-all-special-list-scan.patch b/defects/transformers-0003/patch/transformers-0003-convert-tokens-all-special-list-scan.patch index 8103492f0..997148a39 100644 --- a/defects/transformers-0003/patch/transformers-0003-convert-tokens-all-special-list-scan.patch +++ b/defects/transformers-0003/patch/transformers-0003-convert-tokens-all-special-list-scan.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001171 # transformers-0003: convert_tokens_to_string O(T×S) list scan for special tokens # CWE-407 — Algorithmic Complexity # MOAD-0001 — The Sedimentary Defect diff --git a/defects/unbound-0001/patch/unbound-0001-authzone-rdata-duplicate-O-N2.patch b/defects/unbound-0001/patch/unbound-0001-authzone-rdata-duplicate-O-N2.patch index d61c38af6..b67f44a19 100644 --- a/defects/unbound-0001/patch/unbound-0001-authzone-rdata-duplicate-O-N2.patch +++ b/defects/unbound-0001/patch/unbound-0001-authzone-rdata-duplicate-O-N2.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001172 # UNDF: --- a/services/authzone.c +++ b/services/authzone.c diff --git a/defects/vita3k-0001/patch/vita3k-0001.patch b/defects/vita3k-0001/patch/vita3k-0001.patch index 50bc135c3..7748cec71 100644 --- a/defects/vita3k-0001/patch/vita3k-0001.patch +++ b/defects/vita3k-0001/patch/vita3k-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001173 # UNDF: UNDF-2026-XXXXXXXXX --- a/vita3k/ngs/src/route.cpp +++ b/vita3k/ngs/src/route.cpp diff --git a/defects/vlc-0003/patch/vlc-0003.patch b/defects/vlc-0003/patch/vlc-0003.patch index 4b34fa960..6c39e5445 100644 --- a/defects/vlc-0003/patch/vlc-0003.patch +++ b/defects/vlc-0003/patch/vlc-0003.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001174 # UNDF: (leave blank) # CWE-312: Cleartext Storage of Sensitive Information # VLC SMB1 DSM access module logs SMB credentials (username + domain) at WARN level. diff --git a/defects/vllm-0002/patch/vllm-0002-grok2-special-token-values-scan.patch b/defects/vllm-0002/patch/vllm-0002-grok2-special-token-values-scan.patch index e8655c9f9..04f8db51a 100644 --- a/defects/vllm-0002/patch/vllm-0002-grok2-special-token-values-scan.patch +++ b/defects/vllm-0002/patch/vllm-0002-grok2-special-token-values-scan.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001175 # vllm-0002: Grok2Tokenizer decode/convert_ids_to_tokens O(N×S) dict.values() scan # CWE-407 — Algorithmic Complexity # diff --git a/defects/wekan-0003/patch/wekan-0003.patch b/defects/wekan-0003/patch/wekan-0003.patch index b80663ab2..cc1f36c19 100644 --- a/defects/wekan-0003/patch/wekan-0003.patch +++ b/defects/wekan-0003/patch/wekan-0003.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001176 --- a/models/wekanCreator.js +++ b/models/wekanCreator.js @@ -323,11 +323,13 @@ class WekanCreator { diff --git a/defects/woodpecker-0001/patch/0001-step-builder-filter-items-hashmap.patch b/defects/woodpecker-0001/patch/0001-step-builder-filter-items-hashmap.patch index bb91bb909..a71a48089 100644 --- a/defects/woodpecker-0001/patch/0001-step-builder-filter-items-hashmap.patch +++ b/defects/woodpecker-0001/patch/0001-step-builder-filter-items-hashmap.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001177 diff --git a/server/pipeline/step_builder/step_builder.go b/server/pipeline/step_builder/step_builder.go index abcdef0..1234567 100644 --- a/server/pipeline/step_builder/step_builder.go diff --git a/defects/woodpecker-0002/patch/0001-token-parserequest-cwe312-fix.patch b/defects/woodpecker-0002/patch/0001-token-parserequest-cwe312-fix.patch index be5f5151d..30170b6f8 100644 --- a/defects/woodpecker-0002/patch/0001-token-parserequest-cwe312-fix.patch +++ b/defects/woodpecker-0002/patch/0001-token-parserequest-cwe312-fix.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001178 diff --git a/shared/token/token.go b/shared/token/token.go index abcdef0..1234567 100644 --- a/shared/token/token.go diff --git a/defects/xenia-0001/patch/xenia-0001.patch b/defects/xenia-0001/patch/xenia-0001.patch index 85fd5bdd0..1912cbd31 100644 --- a/defects/xenia-0001/patch/xenia-0001.patch +++ b/defects/xenia-0001/patch/xenia-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001179 --- a/src/xenia/kernel/util/object_table.cc +++ b/src/xenia/kernel/util/object_table.cc @@ -9,6 +9,7 @@ diff --git a/defects/yabause-0001/patch/yabause-0001.patch b/defects/yabause-0001/patch/yabause-0001.patch index b763e6815..97c20d122 100644 --- a/defects/yabause-0001/patch/yabause-0001.patch +++ b/defects/yabause-0001/patch/yabause-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001180 # UNDF: UNDF-2026-XXXXXXXXX --- a/yabause/src/netlink.c +++ b/yabause/src/netlink.c diff --git a/defects/zephyr-0001/patch/zephyr-0001.patch b/defects/zephyr-0001/patch/zephyr-0001.patch index 271bc85ef..7e1732957 100644 --- a/defects/zephyr-0001/patch/zephyr-0001.patch +++ b/defects/zephyr-0001/patch/zephyr-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001181 --- a/subsys/net/lib/wifi_credentials/wifi_credentials_shell.c +++ b/subsys/net/lib/wifi_credentials/wifi_credentials_shell.c @@ -49,17 +49,17 @@ static void print_network_info(void *cb_arg, const char *ssid, size_t ssid_len) diff --git a/defects/zephyr-0002/patch/zephyr-0002.patch b/defects/zephyr-0002/patch/zephyr-0002.patch index ad2838776..08e531d12 100644 --- a/defects/zephyr-0002/patch/zephyr-0002.patch +++ b/defects/zephyr-0002/patch/zephyr-0002.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001182 --- a/subsys/net/l2/wifi/wifi_mgmt.c +++ b/subsys/net/l2/wifi/wifi_mgmt.c @@ -396,9 +396,14 @@ static int wifi_connect(uint64_t mgmt_request, struct net_if *iface, diff --git a/defects/zesarux-0001/patch/zesarux-0001.patch b/defects/zesarux-0001/patch/zesarux-0001.patch index 34e27785b..fa0ca867e 100644 --- a/defects/zesarux-0001/patch/zesarux-0001.patch +++ b/defects/zesarux-0001/patch/zesarux-0001.patch @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000001183 # UNDF: UNDF-2026-XXXXXXXXX --- a/src/zrcp/remote.c +++ b/src/zrcp/remote.c