PT-2026-98311 · Unknown · Gerrit Code Review

·

CVE-2026-87721

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Gerrit Code Review versions 2.0.19 through 3.12.9 Gerrit Code Review versions 3.13.0 through 3.13.8 Gerrit Code Review versions 3.14.0 through 3.14.2
Description Uncontrolled resource consumption in the ANTLR 3 search query parser (QueryParser / Query.g) allows an unauthenticated remote attacker or an authenticated user to cause a persistent denial of service. This occurs via crafted search queries containing deeply nested parentheses sent to the following endpoints: '/changes/?q=', '/accounts/?q=', '/groups/?query=', '/projects/?query=', '/Documentation/?q=', '/changes/{id}/query?expression=', or SSH gerrit query. The issue stems from syntactic predicates in conditionOr and conditionAnd that recurse via conditionBase without memoization—a technique used to store results of expensive function calls to avoid redundant computations—prior to capability or visibility checks. Because worker threads do not abort upon client disconnection, a small number of requests can exhaust the CPU and starve the HTTP worker thread pool, requiring a server restart.
Recommendations Update Gerrit Code Review versions 2.0.19 through 3.12.9 to version 3.12.10. Update Gerrit Code Review versions 3.13.0 through 3.13.8 to version 3.13.9. Update Gerrit Code Review versions 3.14.0 through 3.14.2 to version 3.14.3.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87721

Affected Products

Gerrit Code Review