Skip to content

Fix CPE matching, search deadlines, and review findings - #159

Merged
jdaigneau5 merged 8 commits into
devfrom
af/review-remediations
Sep 30, 2026
Merged

jdaigneau5 merged 8 commits into
devfrom
af/review-remediations

Conversation

@afoote-mitre

Copy link
Copy Markdown
Collaborator

Summary

Addresses seven findings from the repository review, with one commit per remediation. The changes correct CPE candidate matching and range evaluation, enforce semantic-search deadlines, tighten readiness/configuration checks, sanitize terminal errors, and repair Postman fault-test opt-in behavior.

Why These Changes Were Needed

Change Why It Was Needed Primary Files
Preserve escaped CPE components in candidate queries A wildcard component previously stopped at any colon, including a backslash-escaped colon belonging inside a component. Valid CPEs could therefore be excluded before semantic matching. Candidate patterns now consume escaped characters without treating them as separators. utils/cpe.js; regression expectations in utils/cpe.test.js, utils/searchQueryBuilder.test.js, and controllers/searchController.test.js
Reject empty stored version intervals Checking only whether two intervals crossed each other's bounds could treat an inverted stored interval, or an equal-bound interval with an exclusive endpoint, as a match. Each interval is now checked for validity before overlap is evaluated. utils/cpe.js, utils/cpe.test.js, README.md
Enforce deadlines during semantic filtering Synchronous filtering could prevent the timeout callback from running until after the work completed. Filtering now checks a monotonic deadline between candidates and yields to the event loop every 100 candidates, allowing cancellation and deadline handling to run. The controller awaits filtering before fetching the final page. This is cooperative cancellation, not hard preemption of a single synchronous operation. utils/searchDeadline.js, utils/searchPostFilters.js, controllers/searchController.js; corresponding tests and README.md
Reject conflicting mapped field types during readiness checks An acceptable field type could hide an incompatible type reported for the same field across an index alias. Readiness now requires every reported mapped type for the checked field to meet its type, searchability, and required aggregation capabilities. utils/searchReadiness.js, utils/searchReadiness.test.js, utils/searchProvider.test.js, README.md
Honor environment-level Postman fault-test settings Manual fault checks read only the collection variable, ignoring the documented environment-level opt-in. An explicitly configured environment value now takes precedence, with the collection value used only when the environment setting is absent. Only the string true enables these checks. test/postman/buildCollection.js, test/postman/CVE-Search-API.postman_collection.json, test/postman/collection.test.js, test/postman/README.md
Sanitize terminal parser and server errors Errors passed to Express's default handler could produce HTML or expose exception details in development. Unsent responses now use sanitized JSON for oversized bodies, unsupported encodings, other request errors, and unexpected server errors. Existing malformed-JSON and /search content-type responses are preserved; errors after headers are sent still use Express's connection handling. server.js, utils/errors.js, server.test.js, routes/index.js, api-docs/openapi.json, api-docs/openapi.test.js, README.md
Bound configured timeouts to Node's timer range Oversized timeout values can overflow Node timers and effectively trigger an immediate timeout. Readiness, OpenSearch request, and overall search timeouts now accept integers from 1 through 2,147,483,647 ms; invalid values use their existing defaults. utils/constants.js, utils/searchProvider.js, utils/searchProvider.test.js, README.md

Scope

  • Keeps the existing 10,000-candidate limit and pagination behavior; this PR does not implement PIT.
  • Does not change cve-core or introduce caching, queueing, or rate limiting.
  • Keeps /webSearch supported.
  • Updates checked-in OpenAPI and Postman artifacts alongside their sources.

@afoote-mitre afoote-mitre self-assigned this Sep 30, 2026
@jdaigneau5
jdaigneau5 merged commit b765b9a into dev Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants