This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch misc-hardening__MATH-1691
in repository https://gitbox.apache.org/repos/asf/commons-math.git

commit da3d79c0d430ca989dd20dc7617f19cfb7324e7f
Author: Gilles Sadowski <[email protected]>
AuthorDate: Sun Sep 27 18:44:37 2026 +0200

    MATH-1691: Abort early on non finite input.
    
    Found by a security scan.
---
 .../commons/math4/legacy/fitting/SimpleCurveFitter.java   | 15 +++++++++++----
 1 file changed, 11 insertions(+), 4 deletions(-)

diff --git 
a/commons-math-legacy/src/main/java/org/apache/commons/math4/legacy/fitting/SimpleCurveFitter.java
 
b/commons-math-legacy/src/main/java/org/apache/commons/math4/legacy/fitting/SimpleCurveFitter.java
index 012c913ef..6b5c03670 100644
--- 
a/commons-math-legacy/src/main/java/org/apache/commons/math4/legacy/fitting/SimpleCurveFitter.java
+++ 
b/commons-math-legacy/src/main/java/org/apache/commons/math4/legacy/fitting/SimpleCurveFitter.java
@@ -24,6 +24,7 @@ import java.util.ArrayList;
 
 import org.apache.commons.math4.legacy.exception.ZeroException;
 import org.apache.commons.math4.legacy.exception.OutOfRangeException;
+import org.apache.commons.math4.legacy.exception.NotFiniteNumberException;
 import org.apache.commons.math4.legacy.analysis.ParametricUnivariateFunction;
 import 
org.apache.commons.math4.legacy.fitting.leastsquares.LeastSquaresBuilder;
 import 
org.apache.commons.math4.legacy.fitting.leastsquares.LeastSquaresProblem;
@@ -134,8 +135,14 @@ public class SimpleCurveFitter extends AbstractCurveFitter 
{
 
         int count = 0;
         for (WeightedObservedPoint obs : observations) {
-            target[count]  = obs.getY();
-            weights[count] = obs.getWeight();
+            final double v = obs.getY();
+            final double w = obs.getWeight();
+
+            NotFiniteNumberException.check(v);
+            NotFiniteNumberException.check(w);
+
+            target[count]  = v;
+            weights[count] = w;
             ++count;
         }
 
@@ -318,8 +325,8 @@ public class SimpleCurveFitter extends AbstractCurveFitter {
         private boolean isBetween(double value,
                                   double boundary1,
                                   double boundary2) {
-            return (value >= boundary1 && value <= boundary2) ||
-                (value >= boundary2 && value <= boundary1);
+            return value >= boundary1 && value <= boundary2 ||
+                value >= boundary2 && value <= boundary1;
         }
     }
 }

Reply via email to