PT-2026-98311 · Unknown · Gerrit Code Review
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Gerrit Code Review versions 2.0.19 through 3.12.9
Gerrit Code Review versions 3.13.0 through 3.13.8
Gerrit Code Review versions 3.14.0 through 3.14.2
Description
Uncontrolled resource consumption in the ANTLR 3 search query parser (QueryParser / Query.g) allows an unauthenticated remote attacker or an authenticated user to cause a persistent denial of service. This occurs via crafted search queries containing deeply nested parentheses sent to the following endpoints: '/changes/?q=', '/accounts/?q=', '/groups/?query=', '/projects/?query=', '/Documentation/?q=', '/changes/{id}/query?expression=', or SSH gerrit query. The issue stems from syntactic predicates in
conditionOr and conditionAnd that recurse via conditionBase without memoization—a technique used to store results of expensive function calls to avoid redundant computations—prior to capability or visibility checks. Because worker threads do not abort upon client disconnection, a small number of requests can exhaust the CPU and starve the HTTP worker thread pool, requiring a server restart.Recommendations
Update Gerrit Code Review versions 2.0.19 through 3.12.9 to version 3.12.10.
Update Gerrit Code Review versions 3.13.0 through 3.13.8 to version 3.13.9.
Update Gerrit Code Review versions 3.14.0 through 3.14.2 to version 3.14.3.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gerrit Code Review