VYPR
Medium severity4.3NVD Advisory· Published Jul 20, 2021· Updated Jun 17, 2026

CVE-2021-32763

CVE-2021-32763

Description

OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the MessagesController class of OpenProject has a quote method that implements the logic behind the Quote button in the discussion forums, and it uses a regex to strip ` tags from the message being quoted. The (.|\s) part can match a space character in two ways, so an unterminated tag containing n` spaces causes Ruby's regex engine to backtrack to try 2n states in the NFA. This will result in a Regular Expression Denial of Service. The issue is fixed in OpenProject 11.3.3. As a workaround, one may install the patch manually.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Opf/Openproject3 versions
    cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*range: <11.3.3
    • (no CPE)range: <11.3.3
    • (no CPE)range: < 11.3.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.