1.6 KiB
UNDF: UNDF-2026-000000392
etcd CWE-407 Deeper Scan — CLEAN
Date: 2026-03-27
Repo: https://github.com/etcd-io/etcd
Scan scope: server/etcdserver/, server/storage/mvcc/, server/embed/, raft/
Prior status: etcd-CLEAN.md confirmed no defects in initial scan
Re-verification
Scanned for slices.Contains, strings.Contains (membership context), and any
for ... range loops with inner linear membership tests.
Results
All strings.Contains calls in production code paths are substring checks on error
message strings or content-type headers — not slice membership tests. No method named
slices.Contains or ContainsString appears anywhere in server/ or raft/
non-test source files.
The strings.Contains calls found:
| File | Usage |
|---|---|
server/embed/config.go:1092 |
Substring check on peer URL string for "https://" |
server/embed/serve.go:312 |
Content-Type header substring match for gRPC detection |
server/etcdmain/etcd.go:144 |
Error message substring check |
server/etcdserver/corrupt.go:606–613 |
Error message substring checks |
server/etcdserver/cluster_util.go:340–343 |
Error message substring checks |
server/etcdserver/api/v2store/watcher_hub.go:198 |
Path prefix substring check |
server/storage/backend/verify.go:64 |
Stack trace substring check |
None of these are slice membership tests inside scaling loops.
Summary
etcd confirmed CLEAN. No new CWE-407 defects found in the deeper scan.
etcd's watcher machinery uses maps (map[string]watcherSet) and interval trees —
O(1) and O(log N) membership — throughout.