PT-2026-98312 · Unknown · Gerrit Code Review
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Gerrit Code Review versions 2.1.6 through 3.12.9
Gerrit Code Review versions 3.13.0 through 3.13.8
Gerrit Code Review versions 3.14.0 through 3.14.2
Description
Uncontrolled resource consumption occurs in regex search query predicates, including
RegexProjectPredicate, RegexRefPredicate, and RegexPathPredicate, as well as REST regex filter endpoints '/projects/?r=' and '/projects/{project}/branches/?r='. An unauthenticated remote attacker or an authenticated user can cause a denial of service resulting in CPU starvation and JVM heap exhaustion (OutOfMemoryError) by submitting crafted search queries or REST API requests. The issue arises because user-supplied regular expressions are compiled into an unbounded dk.brics.automaton instance via the new RegExp(re).toAutomaton() function on the request thread before index evaluation or access control filtering. This allows regular expressions with exponential DFA determinization patterns or large counted repetitions to exhaust the JVM heap or pin request threads.Recommendations
Update Gerrit Code Review versions 2.1.6 through 3.12.9 to version 3.12.10.
Update Gerrit Code Review versions 3.13.0 through 3.13.8 to version 3.13.9.
Update Gerrit Code Review versions 3.14.0 through 3.14.2 to version 3.14.3.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gerrit Code Review