Gerrit
This hub aggregates every CVE we track for Gerrit, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
LOW2MEDIUM2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
3
2024-102026-09
Latest CVEs
The 7 most recently published vulnerabilities affecting Gerrit.
- CVE-2026-87722Regular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code Review
- CVE-2026-87721Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review
- CVE-2026-87720Incorrect Authorization via Stale ProjectCache Eviction and Repeated .git Suffixes in Gerrit Code Review
- CVE-2026-2725Improper Authorization in Gerrit allowing Code Review Bypass via "Submitted Together"5.3
- CVE-2021-22553Heap Memory exhaustion in Gerrit6.5
- CVE-2020-8920Overoptimization leads to private information leak in Gerrit3.5
- CVE-2020-8919Information leakage in Gerrit3.5
Product normalization is registry-driven with AI assist and human review. How it works