# UNDF: UNDF-2026-000000126 From 0000001 Mon Sep 17 00:00:00 2001 Subject: [PATCH] CWE-407: jetty-0001 — fix O(V×M) List.contains() in HttpFields.formatCsvExcludingExisting() formatCsvExcludingExisting() iterates over V incoming values and calls existing.getValues().contains() on each. getValues() returns ArrayList, so each lookup is O(M) where M is the existing value count. Total O(V×M). Fix: convert existing values to a HashSet once before the loop, replacing O(M) per-iteration with O(1). CWE: CWE-407 (Inefficient Algorithmic Complexity) Severity: MEDIUM --- .../eclipse/jetty/http/HttpFields.java | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java index aaaaaaa..bbbbbbb 100644 --- a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java +++ b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java @@ -14,6 +14,7 @@ import java.util.ArrayList; import java.util.EnumSet; import java.util.Iterator; import java.util.List; +import java.util.HashSet; +import java.util.Set; @@ -1576,11 +1577,14 @@ public interface HttpFields extends Iterable private static String formatCsvExcludingExisting(QuotedCSV existing, String... values) { boolean add = true; if (existing != null && !existing.isEmpty()) { add = false; + // Build a O(1)-lookup set from existing values once, rather than + // calling ArrayList.contains() — O(M) — on every iteration. + Set existingSet = new HashSet<>(existing.getValues()); for (int i = values.length; i-- > 0; ) { String unquoted = QuotedCSV.unquote(values[i]); - if (existing.getValues().contains(unquoted)) + if (existingSet.contains(unquoted)) values[i] = null; else add = true;