PatchSiren

Gerrit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Gerrit CVE published 2026-09-24

CVE-2026-87722

A vulnerability in Gerrit Code Review allows unauthenticated remote attackers to cause a denial of service via crafted search queries or REST API requests containing regular expressions with large counted repetitions or exponential DFA determinization patterns. This issue affects Gerrit Code Review versions 2.1.6 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2. Defenders should assess exp [truncated]

HIGH Gerrit CVE published 2026-09-24

CVE-2026-87721

CVE-2026-87721 is an Uncontrolled Resource Consumption vulnerability in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2. This issue allows an unauthenticated remote attacker to cause a persistent denial of service via crafted search queries. The vulnerability is fixed in versions 3.12.10, 3.13.9, and 3.14.3.

HIGH Gerrit CVE published 2026-09-24

CVE-2026-87720

CVE-2026-87720 is an Incorrect Authorization vulnerability in Gerrit Code Review, affecting versions 2.16.0 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2. An authenticated user can cause unauthorized disclosure of private repository content and restoration of revoked project-owner administrative privileges via crafted requests. This vulnerability allows an attacker to access private rep [truncated]