Where
-Infinity
0

Vendor Risk Score

See how gerrit compares to other vendors in security performance

View Risk Score →
Severity
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and sibling predicates) and REST regex filter endpoints (RegexListSearcher /projects/?r= and RefFilter /projects/{project}/branches/?r=) in Gerrit Code Review versions 2.1.6 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthenticated remote attacker (or an authenticated user if anonymous read access is disabled) to cause a denial of service (CPU starvation and JVM heap exhaustion / OutOfMemoryError) via crafted search queries or REST API requests containing regular expressions with large counted repetitions or exponential DFA determinization patterns. Because the user-supplied regular expression is compiled into an unbounded dk.brics.automaton instance (new RegExp(re).toAutomaton()) on the request thread prior to index evaluation or access control visibility filtering, trivial queries can exhaust JVM heap or pin request threads regardless of heap size. This issue is fixed in Gerrit Code Review versions 3.12.10, 3.13.9, and 3.14.3.

First published (updated )
Severity
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthenticated remote attacker (or an authenticated user if anonymous read access is disabled) to cause a persistent denial of service (CPU exhaustion and HTTP worker thread pool starvation requiring a server restart) via crafted search queries containing deeply nested parentheses sent to query evaluation endpoints (/changes/?q=, /accounts/?q=, /groups/?query=, /projects/?query=, /Documentation/?q=, /changes/{id}/query?expression=, or SSH gerrit query). Because syntactic predicates in conditionOr and conditionAnd recurse via conditionBase without memoization prior to capability or visibility checks and worker threads do not abort when the client disconnects, a small number of requests (such as 25 requests matching default httpd.maxThreads) can permanently pin all HTTP worker threads. This issue is fixed in Gerrit Code Review versions 3.12.10, 3.13.9, and 3.14.3.

First published (updated )
Severity
7.6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versions 2.16.0 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an authenticated user (or an unauthenticated user if the repository was previously public) to cause unauthorized disclosure of private repository content and durable restoration of revoked project-owner administrative privileges via crafted requests using repeated .git suffixes (such as project.git.git) across REST APIs, Gitiles, or SSH Git commands. Because Gerrit strips only a single terminal .git suffix when constructing the logical ProjectCache key while JGit (FileKey.lenient) resolves the suffixed alias to the same canonical bare repository on disk, revoking read access or removing owner rules on the canonical project name fails to evict the cached alias ProjectState during the cache validity window, enabling reads of newly created private commits or writes to refs/meta/config. This issue is fixed in Gerrit Code Review versions 3.12.10, 3.13.9, and 3.14.3.

First published (updated )

Latest version: 3.14.4

First published (updated )
Severity
6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.

First published (updated )

Latest version: 3.13.10

First published (updated )

Latest version: 3.12.11

First published (updated )
EOL
May 15, 2026

End of life: 5/15/2026, Latest version: 3.11.11

First published (updated )
EOL
May 15, 2026

End of life: 5/15/2026, Latest version: 3.11.11

First published (updated )
EOL
Dec 2, 2024

End of life: 12/2/2024, Latest version: 3.8.10

First published (updated )
EOL
Dec 2, 2024

End of life: 12/2/2024, Latest version: 3.8.10

First published (updated )
EOL
Nov 10, 2025

End of life: 11/10/2025, Latest version: 3.10.9

First published (updated )
EOL
Nov 10, 2025

End of life: 11/10/2025, Latest version: 3.10.9

First published (updated )
EOL
May 19, 2025

End of life: 5/19/2025, Latest version: 3.9.11

First published (updated )
EOL
May 19, 2025

End of life: 5/19/2025, Latest version: 3.9.11

First published (updated )
EOL
May 17, 2024

End of life: 5/17/2024, Latest version: 3.7.9

First published (updated )
EOL
May 17, 2024

End of life: 5/17/2024, Latest version: 3.7.9

First published (updated )
EOL
Nov 25, 2023

End of life: 11/25/2023, Latest version: 3.6.8

First published (updated )
EOL
Nov 25, 2023

End of life: 11/25/2023, Latest version: 3.6.8

First published (updated )
EOL
May 19, 2023

End of life: 5/19/2023, Latest version: 3.5.6

First published (updated )
EOL
May 19, 2023

End of life: 5/19/2023, Latest version: 3.5.6

First published (updated )
EOL
Nov 9, 2022

End of life: 11/9/2022, Latest version: 3.4.8

First published (updated )
EOL
Nov 9, 2022

End of life: 11/9/2022, Latest version: 3.4.8

First published (updated )
EOL
May 24, 2022

End of life: 5/24/2022, Latest version: 3.3.11

First published (updated )
EOL
May 24, 2022

End of life: 5/24/2022, Latest version: 3.3.11

First published (updated )
EOL
Dec 7, 2021

End of life: 12/7/2021, Latest version: 3.2.14

First published (updated )
EOL
Dec 7, 2021

End of life: 12/7/2021, Latest version: 3.2.14

First published (updated )
EOL
May 19, 2021

End of life: 5/19/2021, Latest version: 3.1.16

First published (updated )
EOL
May 19, 2021

End of life: 5/19/2021, Latest version: 3.1.16

First published (updated )
EOL
Dec 1, 2020

End of life: 12/1/2020, Latest version: 3.0.16

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203