---
cve: "CVE-2026-87721"
severity: "HIGH"
cvss: 8.7
epss: "0.3%"
vendor: "Gerrit"
kev: false
exploited: false
published: "2026-09-24 22:17:02"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-01T06:11:32+02:00"
---

# CVE-2026-87721

> 8.7 HIGH

## Beschreibung

Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthenticated remote attacker (or an authenticated user if anonymous read access is disabled) to cause a persistent denial of service (CPU exhaustion and HTTP worker thread pool starvation requiring a server restart) via crafted search queries containing deeply nested parentheses sent to query evaluation endpoints (/changes/?q=, /accounts/?q=, /groups/?query=, /projects/?query=, /Documentation/?q=, /changes/{id}/query?expression=, or SSH gerrit query). Because syntactic predicates in conditionOr and conditionAnd recurse via conditionBase without memoization prior to capability or visibility checks and worker threads do not abort when the client disconnects, a small number of requests (such as 25 requests matching default httpd.maxThreads) can permanently pin all HTTP worker threads. This issue is fixed in Gerrit Code Review versions 3.12.10, 3.13.9, and 3.14.3.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **yes**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Schwachstellen-Klasse

- **CWE-400** — Uncontrolled Resource Consumption
  The product does not properly control the allocation and maintenance of a limited resource.
- **CWE-407** — Inefficient Algorithmic Complexity
  An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

## Angriffsmuster (CAPEC)

- [CAPEC-147 — XML Ping of the Death](https://capec.mitre.org/data/definitions/147.html) _(Severity: Medium)_
- [CAPEC-227 — Sustained Client Engagement](https://capec.mitre.org/data/definitions/227.html)
- [CAPEC-492 — Regular Expression Exponential Blowup](https://capec.mitre.org/data/definitions/492.html)

## ATT&CK-Techniken

- [T1499 — Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499/)

## Referenzen

- <https://issues.gerritcodereview.com/issues/541287630>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-87721) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
