java-topology/defects/httpx/CLEAN.md
russell@unturf.com 0dbb699821 openai SDK dependency chain CWE-407 scan: all 5 targets CLEAN
openai-python, httpx, pydantic, tiktoken, openai-node — no CWE-407 defects.
All targets use proper dict/set/frozenset for membership tests in hot paths.
2026-03-30 16:44:33 -04:00

1,016 B

httpx: CLEAN

CWE-407 scan: 2026-03-30

Source: https://github.com/encode/httpx (depth=1)

Scan scope

  • httpx/ — 23 Python files
  • Focus: header dedup, cookie jar membership, redirect chain dedup, transport pool membership, URL param dedup
  • Keywords: in list, .index(, nested for loops

Findings

No CWE-407 defects found.

  • Headers.__contains__ (line 346-348) creates a list and does linear scan — O(H) per call. Headers.update() calls if key in self in a loop — technically O(K*H), but HTTP headers are bounded (typically < 50) and this is a standard design for case-insensitive multidict.
  • Headers.__setitem__ and __delitem__ also do linear scans over the internal list, but again bounded by header count.
  • Redirect chain bounded by max_redirects (default 20)
  • Cookie handling delegates to stdlib CookieJar
  • QueryParams backed by dict — O(1) lookup

Verdict

CLEAN — all linear scans are on bounded collections (HTTP headers). No unbounded O(N^2) patterns.