java-topology/defects/jetty/patch/jetty-0001.patch
russell@unturf.com 9934133dcf whitepaper: 312 sites / 151 ecosystems — wave2+3 defect tables and PDF rebuild
Add 88 new defect entries to HIGH and MEDIUM tables:
  HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
        vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
        tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
        allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
        mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
        linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
        perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002

  MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
          cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
          pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
          ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
          r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
          ovs-0001, onos-0003, odl-0002, jetty-0001

PDF: 976K
2026-03-27 15:23:43 -04:00

46 lines
2.1 KiB
Diff
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

From 0000001 Mon Sep 17 00:00:00 2001
Subject: [PATCH] CWE-407: jetty-0001 — fix O(V×M) List.contains() in
HttpFields.formatCsvExcludingExisting()
formatCsvExcludingExisting() iterates over V incoming values and calls
existing.getValues().contains() on each. getValues() returns ArrayList<String>,
so each lookup is O(M) where M is the existing value count. Total O(V×M).
Fix: convert existing values to a HashSet<String> once before the loop,
replacing O(M) per-iteration with O(1).
CWE: CWE-407 (Inefficient Algorithmic Complexity)
Severity: MEDIUM
---
.../eclipse/jetty/http/HttpFields.java | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
index aaaaaaa..bbbbbbb 100644
--- a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
+++ b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
@@ -14,6 +14,7 @@ import java.util.ArrayList;
import java.util.EnumSet;
import java.util.Iterator;
import java.util.List;
+import java.util.HashSet;
+import java.util.Set;
@@ -1576,11 +1577,14 @@ public interface HttpFields extends Iterable<HttpField>
private static String formatCsvExcludingExisting(QuotedCSV existing, String... values)
{
boolean add = true;
if (existing != null && !existing.isEmpty())
{
add = false;
+ // Build a O(1)-lookup set from existing values once, rather than
+ // calling ArrayList.contains() — O(M) — on every iteration.
+ Set<String> existingSet = new HashSet<>(existing.getValues());
for (int i = values.length; i-- > 0; )
{
String unquoted = QuotedCSV.unquote(values[i]);
- if (existing.getValues().contains(unquoted))
+ if (existingSet.contains(unquoted))
values[i] = null;
else
add = true;