PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87721 Gerrit CVE debrief

CVE-2026-87721 is an Uncontrolled Resource Consumption vulnerability in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2. This issue allows an unauthenticated remote attacker to cause a persistent denial of service via crafted search queries. The vulnerability is fixed in versions 3.12.10, 3.13.9, and 3.14.3.

Vendor
Gerrit
Product
Unknown
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-25
Advisory published
2026-09-24
Advisory updated
2026-09-25

Who should care

System administrators and security teams responsible for Gerrit Code Review deployments should assess exposure and take action to prevent potential denial-of-service attacks. They should review the vulnerability details, understand the potential impacts, and prioritize patching or mitigating this vulnerability to prevent exploitation. Additionally, operators and platform teams should be aware of the vulnerability and its potential effects on the system.

Why it matters

CVE-2026-87721 is a high-severity vulnerability in Gerrit Code Review that allows unauthenticated remote attackers to cause a persistent denial of service. Defenders should prioritize patching or mitigating this vulnerability to prevent potential impacts.

  • Denial of service via CPU exhaustion and HTTP worker thread pool starvation
  • Potential for persistent impact requiring server restart
  • Need for patching or mitigation to prevent exploitation

Technical summary

The ANTLR 3 search query parser in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 is vulnerable to Uncontrolled Resource Consumption. An unauthenticated remote attacker can cause a persistent denial of service by sending crafted search queries containing deeply nested parentheses to query evaluation endpoints, leading to CPU exhaustion and HTTP worker thread pool starvation requiring a server restart. This issue is fixed in Gerrit Code Review versions 3.12.10, 3.13.9, and 3.14.3.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability to prevent potential denial-of-service attacks. System administrators and security teams responsible for Gerrit Code Review deployments should assess exposure and take action.

Recommended defensive actions

  • Patch Gerrit Code Review to version 3.12.10, 3.13.9, or 3.14.3
  • Restrict access to search query evaluation endpoints
  • Monitor for suspicious search query activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. Additional information on potential exploitation or impact is limited. Defenders should verify affected scope, review official advisories, and assess exposure. Evidence is based on CVE and NVD data, which may have limitations. Further review of vendor documentation and security advisories is recommended to understand the full impact and necessary mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87721 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87721

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87721 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87721

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.