Rocket.chat
82 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Rocket.chat, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Rocket.chat CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 3 |
| 2026-04 | 3 |
| 2026-05 | 2 |
| 2026-06 | 14 |
| 2026-07 | 1 |
| 2026-08 | 6 |
| 2026-09 | 0 |
Severity
How the 82 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical11
- High18
- Medium45
Latest CVEs
The 15 most recently published vulnerabilities affecting Rocket.chat.
- CVE-2026-75575Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method5.3
- CVE-2026-65644Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized...7.5
- CVE-2026-65645Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped par...4.3
- CVE-2026-72919Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams4.3
- CVE-2026-72918Rocket.Chat: Insecure implementation of websocket notifications5.4
- CVE-2026-56845An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker...7.5
- CVE-2026-58066Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:...9.8
- CVE-2026-55762Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint8.1
- CVE-2026-55759Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay7.4
- CVE-2026-55666Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth—
- CVE-2026-49278Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation6.7
- CVE-2026-49277Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation—
- CVE-2026-45757Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens—
- CVE-2026-46423Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty—
- CVE-2026-45689Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO9.1
Product grouping is registry-driven, with AI assist and human review. How it works