PT-2026-98312 · Unknown · Gerrit Code Review

·

CVE-2026-87722

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Gerrit Code Review versions 2.1.6 through 3.12.9 Gerrit Code Review versions 3.13.0 through 3.13.8 Gerrit Code Review versions 3.14.0 through 3.14.2
Description Uncontrolled resource consumption occurs in regex search query predicates, including RegexProjectPredicate, RegexRefPredicate, and RegexPathPredicate, as well as REST regex filter endpoints '/projects/?r=' and '/projects/{project}/branches/?r='. An unauthenticated remote attacker or an authenticated user can cause a denial of service resulting in CPU starvation and JVM heap exhaustion (OutOfMemoryError) by submitting crafted search queries or REST API requests. The issue arises because user-supplied regular expressions are compiled into an unbounded dk.brics.automaton instance via the new RegExp(re).toAutomaton() function on the request thread before index evaluation or access control filtering. This allows regular expressions with exponential DFA determinization patterns or large counted repetitions to exhaust the JVM heap or pin request threads.
Recommendations Update Gerrit Code Review versions 2.1.6 through 3.12.9 to version 3.12.10. Update Gerrit Code Review versions 3.13.0 through 3.13.8 to version 3.13.9. Update Gerrit Code Review versions 3.14.0 through 3.14.2 to version 3.14.3.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87722

Affected Products

Gerrit Code Review