1.2 KiB
1.2 KiB
UNDF: UNDF-2026-000000573
waitress — CWE-407 Scan: CLEAN
Date: 2026-03-27
Scope: Full Python codebase (src/waitress/)
Findings
No CWE-407 defects confirmed.
Patterns examined
| Location | Pattern | Verdict |
|---|---|---|
waitress/parser.py:parse_headers |
key1 in headers — duplicate singleton detection |
CLEAN — self.headers is a dict, membership is O(1) |
waitress/task.py:build_response_header |
for headername, headerval in self.response_headers |
CLEAN — single-pass, no inner membership scan during the loop |
waitress/task.py:set_close_on_finish |
iterates response_headers for "Connection" header |
NOT O(n²) — called at most 2-3 times per response after the main loop completes, not inside it |
waitress/server.py:active_channels |
channel management | CLEAN — active_channels is a dict |
waitress/task.py:ThreadedTaskDispatcher |
thread management | CLEAN — threads is a set |
waitress/proxy_headers.py |
proxy header parsing | CLEAN — linear passes only, no nested scans |
Conclusion
Waitress uses dicts for all hot-path lookup structures. The response header
list in task.py is iterated linearly without nested membership tests.