Medium severity4.3NVD Advisory· Published Jul 20, 2021· Updated Jun 17, 2026
CVE-2021-32763
CVE-2021-32763
Description
OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the MessagesController class of OpenProject has a quote method that implements the logic behind the Quote button in the discussion forums, and it uses a regex to strip ` tags from the message being quoted. The (.|\s) part can match a space character in two ways, so an unterminated tag containing n` spaces causes Ruby's regex engine to backtrack to try 2n states in the NFA. This will result in a Regular Expression Denial of Service. The issue is fixed in OpenProject 11.3.3. As a workaround, one may install the patch manually.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*range: <11.3.3
- (no CPE)range: <11.3.3
- (no CPE)range: < 11.3.3
Patches
Vulnerability mechanics
References
2- github.com/opf/openproject/pull/9447.patchnvdPatchThird Party Advisory
- github.com/opf/openproject/security/advisories/GHSA-qqvp-j6gm-q56fnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.