47 lines
2.1 KiB
Diff
47 lines
2.1 KiB
Diff
# UNDF: UNDF-2026-000000126
|
||
From 0000001 Mon Sep 17 00:00:00 2001
|
||
Subject: [PATCH] CWE-407: jetty-0001 — fix O(V×M) List.contains() in
|
||
HttpFields.formatCsvExcludingExisting()
|
||
|
||
formatCsvExcludingExisting() iterates over V incoming values and calls
|
||
existing.getValues().contains() on each. getValues() returns ArrayList<String>,
|
||
so each lookup is O(M) where M is the existing value count. Total O(V×M).
|
||
|
||
Fix: convert existing values to a HashSet<String> once before the loop,
|
||
replacing O(M) per-iteration with O(1).
|
||
|
||
CWE: CWE-407 (Inefficient Algorithmic Complexity)
|
||
Severity: MEDIUM
|
||
---
|
||
.../eclipse/jetty/http/HttpFields.java | 8 ++++++--
|
||
1 file changed, 6 insertions(+), 2 deletions(-)
|
||
|
||
diff --git a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
|
||
index aaaaaaa..bbbbbbb 100644
|
||
--- a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
|
||
+++ b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
|
||
@@ -14,6 +14,7 @@ import java.util.ArrayList;
|
||
import java.util.EnumSet;
|
||
import java.util.Iterator;
|
||
import java.util.List;
|
||
+import java.util.HashSet;
|
||
+import java.util.Set;
|
||
|
||
@@ -1576,11 +1577,14 @@ public interface HttpFields extends Iterable<HttpField>
|
||
private static String formatCsvExcludingExisting(QuotedCSV existing, String... values)
|
||
{
|
||
boolean add = true;
|
||
if (existing != null && !existing.isEmpty())
|
||
{
|
||
add = false;
|
||
+ // Build a O(1)-lookup set from existing values once, rather than
|
||
+ // calling ArrayList.contains() — O(M) — on every iteration.
|
||
+ Set<String> existingSet = new HashSet<>(existing.getValues());
|
||
for (int i = values.length; i-- > 0; )
|
||
{
|
||
String unquoted = QuotedCSV.unquote(values[i]);
|
||
- if (existing.getValues().contains(unquoted))
|
||
+ if (existingSet.contains(unquoted))
|
||
values[i] = null;
|
||
else
|
||
add = true;
|