From 856f21749b0a4d7ed496ec3c33568221c2a35ad4 Mon Sep 17 00:00:00 2001 From: Mauro Baluda Date: Sat, 3 Oct 2026 18:59:27 +0200 Subject: [PATCH 1/2] Refactor HttpStringLiteral Materialize HTTP string candidates before computing recursive parent relations, allowing the RA plan to restrict getParent*() and the subsequent private-host antijoin to the filtered candidate set. --- cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql b/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql index 682d83874333..e8014c33fd21 100644 --- a/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql +++ b/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql @@ -38,19 +38,22 @@ predicate privateHostNameFlowsToExpr(Expr e) { /** * A string containing an HTTP URL not in a private domain. */ -class HttpStringLiteral extends StringLiteral { - HttpStringLiteral() { +private class HttpStringLiteralCandidate extends StringLiteral { + HttpStringLiteralCandidate() { exists(string s | this.getValue() = s | s = "http" or exists(string tail | tail = s.regexpCapture("http://(.*)", 1) and not tail instanceof PrivateHostName ) - ) and - not privateHostNameFlowsToExpr(this.getParent*()) + ) } } +class HttpStringLiteral extends HttpStringLiteralCandidate { + HttpStringLiteral() { not privateHostNameFlowsToExpr(this.getParent*()) } +} + /** * Taint tracking configuration for HTTP connections. */ From 1c10fcae4caec265ed253eab68a711ad90fe6242 Mon Sep 17 00:00:00 2001 From: Mauro Baluda Date: Mon, 5 Oct 2026 17:56:44 +0200 Subject: [PATCH 2/2] Move HttpStringLiteral class documentation --- cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql b/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql index e8014c33fd21..1cb3be1f0c91 100644 --- a/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql +++ b/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql @@ -35,9 +35,6 @@ predicate privateHostNameFlowsToExpr(Expr e) { TaintTracking::localExprTaint(any(StringLiteral p | p.getValue() instanceof PrivateHostName), e) } -/** - * A string containing an HTTP URL not in a private domain. - */ private class HttpStringLiteralCandidate extends StringLiteral { HttpStringLiteralCandidate() { exists(string s | this.getValue() = s | @@ -50,6 +47,9 @@ private class HttpStringLiteralCandidate extends StringLiteral { } } +/** + * A string containing an HTTP URL not in a private domain. + */ class HttpStringLiteral extends HttpStringLiteralCandidate { HttpStringLiteral() { not privateHostNameFlowsToExpr(this.getParent*()) } }