Incorrect Authorization in Gerrit Code Review Software by Gerrit Code Review
CVE-2026-87720
What is CVE-2026-87720?
An incorrect authorization flaw has been identified in Gerrit Code Review that allows both authenticated and unauthenticated users to gain unauthorized access to private repository content. This vulnerability arises from an issue in the project name normalization and ProjectCache eviction logic. It permits crafted requests with multiple .git suffixes to bypass security measures. Specifically, the system only strips one terminal .git suffix from the project name, enabling potential unauthorized disclosures and the restoration of previously revoked administrative privileges. The issue affects several versions of the software, necessitating immediate updates to leverage the latest security patches.
Affected Version(s)
Gerrit 2.16.0 < 3.12.10
Gerrit 3.13.0 < 3.13.9
Gerrit 3.14.0 < 3.14.3
