Skip to content

Menu
  • Home
Menu

CVE-2026-87721 – Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review

Posted on September 25, 2026
CVE ID :CVE-2026-87721

Published : Sept. 24, 2026, 10:17 p.m. | 1 hour, 50 minutes ago

Description :Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthenticated remote attacker (or an authenticated user if anonymous read access is disabled) to cause a persistent denial of service (CPU exhaustion and HTTP worker thread pool starvation requiring a server restart) via crafted search queries containing deeply nested parentheses sent to query evaluation endpoints (/changes/?q=, /accounts/?q=, /groups/?query=, /projects/?query=, /Documentation/?q=, /changes/{id}/query?expression=, or SSH gerrit query). Because syntactic predicates in conditionOr and conditionAnd recurse via conditionBase without memoization prior to capability or visibility checks and worker threads do not abort when the client disconnects, a small number of requests (such as 25 requests matching default httpd.maxThreads) can permanently pin all HTTP worker threads. This issue is fixed in Gerrit Code Review versions 3.12.10, 3.13.9, and 3.14.3.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-87721

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

1.1 Assess Exposure: Immediately identify all instances of GlobalApp Server versions 3.0.0 through 3.4.9 within your environment. Prioritize systems that are publicly accessible or handle sensitive data.
1.2 Network Isolation: If immediate patching is not feasible, consider temporarily isolating critical GlobalApp Server instances from untrusted networks or placing

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 2

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme