{"api_version":"1","generated_at":"2026-07-24T02:25:16+00:00","cve":"CVE-2021-32832","urls":{"html":"https://cve.report/CVE-2021-32832","api":"https://cve.report/api/cve/CVE-2021-32832.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-32832","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-32832"},"summary":{"title":"CVE-2021-32832","description":"Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-08-30 21:15:00","updated_at":"2021-09-08 13:42:00"},"problem_types":["CWE-400"],"metrics":[],"references":[{"url":"https://github.com/RocketChat/Rocket.Chat/releases/tag/3.11.3","name":"https://github.com/RocketChat/Rocket.Chat/releases/tag/3.11.3","refsource":"MISC","tags":[],"title":"Release 3.11.3 · RocketChat/Rocket.Chat · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://securitylab.github.com/advisories/GHSL-2020-310-redos-Rocket.Chat/","name":"https://securitylab.github.com/advisories/GHSL-2020-310-redos-Rocket.Chat/","refsource":"CONFIRM","tags":[],"title":"GHSL-2020-310: ReDoS (Regular Expression Denial of Service) in Rocket Chat - CVE-2021-32832 | GitHub Security Lab","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.rocket.chat/guides/security/security-updates","name":"https://docs.rocket.chat/guides/security/security-updates","refsource":"MISC","tags":[],"title":"Security fixes and updates - Rocket.Chat Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/RocketChat/Rocket.Chat/commit/4a0dce973e37ec3f56ca2231d6030511dbdd094c","name":"https://github.com/RocketChat/Rocket.Chat/commit/4a0dce973e37ec3f56ca2231d6030511dbdd094c","refsource":"MISC","tags":[],"title":"Bump version to 3.11.3 · RocketChat/Rocket.Chat@4a0dce9 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-32832","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32832","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"32832","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rocket.chat","cpe5":"rocket.chat","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-32832","STATE":"PUBLIC","TITLE":"ReDOS in Rocket.Chat"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Rocket.Chat","version":{"version_data":[{"version_value":"< 3.11.3"}]}}]},"vendor_name":"RocketChat"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-400 Uncontrolled Resource Consumption"}]}]},"references":{"reference_data":[{"name":"https://docs.rocket.chat/guides/security/security-updates","refsource":"MISC","url":"https://docs.rocket.chat/guides/security/security-updates"},{"name":"https://securitylab.github.com/advisories/GHSL-2020-310-redos-Rocket.Chat/","refsource":"CONFIRM","url":"https://securitylab.github.com/advisories/GHSL-2020-310-redos-Rocket.Chat/"},{"name":"https://github.com/RocketChat/Rocket.Chat/releases/tag/3.11.3","refsource":"MISC","url":"https://github.com/RocketChat/Rocket.Chat/releases/tag/3.11.3"},{"name":"https://github.com/RocketChat/Rocket.Chat/commit/4a0dce973e37ec3f56ca2231d6030511dbdd094c","refsource":"MISC","url":"https://github.com/RocketChat/Rocket.Chat/commit/4a0dce973e37ec3f56ca2231d6030511dbdd094c"}]},"source":{"defect":["GHSL-2020-310"],"discovery":"INTERNAL"}},"nvd":{"publishedDate":"2021-08-30 21:15:00","lastModifiedDate":"2021-09-08 13:42:00","problem_types":["CWE-400"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*","versionEndExcluding":"3.11.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*","versionStartIncluding":"3.12.0","versionEndExcluding":"3.12.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"32832","Ordinal":"208220","Title":"CVE-2021-32832","CVE":"CVE-2021-32832","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"32832","Ordinal":"1","NoteData":"Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"32832","Ordinal":"2","NoteData":"2021-08-30","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"32832","Ordinal":"3","NoteData":"2021-08-30","Type":"Other","Title":"Modified"}]}}}