java-topology/defects/jetty/patch/jetty-0001.patch

47 lines
2.1 KiB
Diff
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# UNDF: UNDF-2026-000000126
From 0000001 Mon Sep 17 00:00:00 2001
Subject: [PATCH] CWE-407: jetty-0001 — fix O(V×M) List.contains() in
HttpFields.formatCsvExcludingExisting()
formatCsvExcludingExisting() iterates over V incoming values and calls
existing.getValues().contains() on each. getValues() returns ArrayList<String>,
so each lookup is O(M) where M is the existing value count. Total O(V×M).
Fix: convert existing values to a HashSet<String> once before the loop,
replacing O(M) per-iteration with O(1).
CWE: CWE-407 (Inefficient Algorithmic Complexity)
Severity: MEDIUM
---
.../eclipse/jetty/http/HttpFields.java | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
index aaaaaaa..bbbbbbb 100644
--- a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
+++ b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
@@ -14,6 +14,7 @@ import java.util.ArrayList;
import java.util.EnumSet;
import java.util.Iterator;
import java.util.List;
+import java.util.HashSet;
+import java.util.Set;
@@ -1576,11 +1577,14 @@ public interface HttpFields extends Iterable<HttpField>
private static String formatCsvExcludingExisting(QuotedCSV existing, String... values)
{
boolean add = true;
if (existing != null && !existing.isEmpty())
{
add = false;
+ // Build a O(1)-lookup set from existing values once, rather than
+ // calling ArrayList.contains() — O(M) — on every iteration.
+ Set<String> existingSet = new HashSet<>(existing.getValues());
for (int i = values.length; i-- > 0; )
{
String unquoted = QuotedCSV.unquote(values[i]);
- if (existing.getValues().contains(unquoted))
+ if (existingSet.contains(unquoted))
values[i] = null;
else
add = true;