PT-2026-98310 · Unknown · Gerrit Code Review

·

CVE-2026-87720

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gerrit Code Review versions 2.16.0 through 3.12.9 Gerrit Code Review versions 3.13.0 through 3.13.8 Gerrit Code Review versions 3.14.0 through 3.14.2
Description Incorrect authorization occurs during project name normalization in ProjectUtil.stripGitSuffix() and project cache eviction in ProjectCacheImpl. An authenticated user, or an unauthenticated user if the repository was previously public, can cause unauthorized disclosure of private repository content and restore revoked project-owner administrative privileges. This is achieved through crafted requests using repeated .git suffixes (e.g., project.git.git) across REST APIs, Gitiles, or SSH Git commands. The issue arises because the system strips only a single terminal .git suffix when creating the logical ProjectCache key, while JGit resolves the suffixed alias to the same canonical bare repository on disk. Consequently, revoking read access or removing owner rules on the canonical project name fails to evict the cached alias ProjectState during the cache validity window, allowing reads of private commits or writes to refs/meta/config.
Recommendations Update Gerrit Code Review versions 2.16.0 through 3.12.9 to version 3.12.10. Update Gerrit Code Review versions 3.13.0 through 3.13.8 to version 3.13.9. Update Gerrit Code Review versions 3.14.0 through 3.14.2 to version 3.14.3.

Exploit

Fix

Incorrect Authorization

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87720

Affected Products

Gerrit Code Review