The exclusion I wonder about is CWE-1333 (ReDoS): disclaimed at the
baseline; counts as excessive CPU under “secure parsing”.

Algorithms for handling regexps that do not have exponential behavior
are known. I recall that moving to these at Google was a big deal over
several years that had real practical improvements across the company
in performance and security. Maybe note that this is not something we
have done yet, but it is something we should do and then we should be
able to make this promise.

On Tue, Sep 22, 2026 at 7:11 PM Gary D. Gregory <[email protected]> wrote:
>
> Fixed typo in the subject.
>
> Gary
>
> On 2026/09/22 17:47:18 Gary Gregory wrote:
> > Hi All,
> >
> > Thank you to Piotr for helping get our threat model off the ground.
> >
> > Please review for content and typos, if you feel so inclined:
> >
> > - https://commons.apache.org/threat-model-short-0.1.0.html
> > - https://commons.apache.org/threat-model-0.1.0.html
> >
> > Both are linked from https://commons.apache.org/security.html
> >
> > TY,
> > Gary
> >
> > ---------------------------------------------------------------------
> > To unsubscribe, e-mail: [email protected]
> > For additional commands, e-mail: [email protected]
> >
> >
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>


-- 
Elliotte Rusty Harold
[email protected]

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to