Skip to content

Resolves #110, #111, #112, #113, and #114: Fix CPE matching compatibility and applicability edge cases - #117

Merged
jdaigneau5 merged 7 commits into
devfrom
af/cpe-filtering-fixes
Aug 3, 2026
Merged

jdaigneau5 merged 7 commits into
devfrom
af/cpe-filtering-fixes

Conversation

@afoote-mitre

Copy link
Copy Markdown
Collaborator

Summary

Resolves #110, #111, #112, #113, and #114

This branch corrects CPE Name applicability and version comparison edge cases, aligning /search behavior with the CPE 2.3 specification and observed NVD API behavior.

Changes

Align CPE NA Range Matching With NVD

  • Treats the CPE logical value - as not applicable rather than as an ordinary version string.
  • Preserves NVD-compatible matches when numeric ranges are applied to -.
  • Continues to reject mismatched exact versions and exclusive - boundaries.

Primary files:

  • utils/cpe.js
  • utils/cpe.test.js
  • controllers/searchController.test.js
  • README.md
  • routes/swagger.js
  • api-docs/openapi.json

Apply Semantic Version Qualifier Ordering

  • Uses the following Maven-style ordering from earliest to latest:
    • alpha / a
    • beta / b
    • milestone / m
    • rc / cr
    • snapshot
    • Unqualified release / ga / final / release
    • sp
    • Unknown qualifiers, including hf, ordered lexically after known qualifiers
  • Treats prerelease versions such as 1.0.0-rc1 as earlier than 1.0.0.
  • Treats service-pack and unknown post-release qualifiers such as 1.0.0-sp1 and 1.0.0-hf1 as later than 1.0.0.
  • Compares qualifier names without regard to lexical case.
  • Applies the ordering consistently to cpeName, virtualMatchString ranges, and range validation.

Primary files:

  • utils/cpe.js
  • utils/cpe.test.js
  • controllers/middleware.test.js
  • routes/swagger.js
  • api-docs/openapi.json
  • README.md

Correlate All CPE Components

  • Requires the same CPE Match Criteria entry to satisfy version, vulnerability, and every concrete non-version component.
  • Prevents applicability ranges for one platform, such as Android or Chrome OS, from satisfying a request for another platform, such as macOS.
  • Keeps optional input components set to * as broad matches.

Primary files:

  • utils/cpe.js
  • utils/cpe.test.js
  • controllers/searchController.test.js
  • routes/swagger.js
  • api-docs/openapi.json
  • README.md

Make CPE Literal Matching Case-Insensitive

  • Implements the CPE 2.3 requirement that string literal comparisons be insensitive to lexical case.
  • Allows inputs such as macos to match stored criteria containing macOS.
  • Applies case-insensitive behavior to cpeName, virtualMatchString, exact versions, and range matching.
  • Adds case_insensitive: true to CPE-specific OpenSearch prefix and regular-expression candidate queries.

Primary files:

  • utils/cpe.js
  • utils/searchQueryBuilder.js
  • utils/cpe.test.js
  • utils/searchQueryBuilder.test.js
  • controllers/searchController.test.js
  • routes/swagger.js
  • api-docs/openapi.json
  • README.md

Document Leading-Zero Range Behavior

  • Documents NVD behavior observed on July 28, 2026.
  • Preserves leading zeros for exact CPE Match Criteria, so 1.0.04.001 and 1.0.4.1 remain distinct.
  • Ignores leading zeros within numeric range comparison, so 6.1 is treated as earlier than an exclusive 6.02 boundary.
  • Warns that this NVD compatibility behavior may not reflect a firmware vendor's actual release sequence.
  • Adds regressions based on CVE-2026-33280 and CVE-2025-9392.

Primary files:

  • utils/cpe.test.js
  • controllers/searchController.test.js
  • README.md
  • routes/swagger.js
  • api-docs/openapi.json
  • api-docs/openapi.test.js

@afoote-mitre
afoote-mitre changed the base branch from main to dev August 3, 2026 17:07
@afoote-mitre
afoote-mitre requested a review from jdaigneau5 August 3, 2026 17:07
@afoote-mitre afoote-mitre self-assigned this Aug 3, 2026
@jdaigneau5
jdaigneau5 merged commit 175011b into dev Aug 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

unexpected results when '-' is in a cpeName value

2 participants