๐Ÿ” CVE Alert

CVE-2026-87721

UNKNOWN 0.0

Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthenticated remote attacker (or an authenticated user if anonymous read access is disabled) to cause a persistent denial of service (CPU exhaustion and HTTP worker thread pool starvation requiring a server restart) via crafted search queries containing deeply nested parentheses sent to query evaluation endpoints (/changes/?q=, /accounts/?q=, /groups/?query=, /projects/?query=, /Documentation/?q=, /changes/{id}/query?expression=, or SSH gerrit query). Because syntactic predicates in conditionOr and conditionAnd recurse via conditionBase without memoization prior to capability or visibility checks and worker threads do not abort when the client disconnects, a small number of requests (such as 25 requests matching default httpd.maxThreads) can permanently pin all HTTP worker threads. This issue is fixed in Gerrit Code Review versions 3.12.10, 3.13.9, and 3.14.3.

CWE CWE-400 CWE-407 CWE-834
Vendor gerrit
Product gerrit
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for gerrit gerrit

Be the first to know when new unknown vulnerabilities affecting gerrit gerrit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gerrit / Gerrit
2.0.19 < 3.12.10 3.13.0 < 3.13.9 3.14.0 < 3.14.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
issues.gerritcodereview.com: https://issues.gerritcodereview.com/issues/541287630

Credits

Amin Alemi