megachangelog
Fix8.2.8

Rocket.Chat 8.2.8

Patch release with security improvements including rate limiting on the unauthenticated sendForgotPasswordEmail method, SSRF protection in file downloads, and fixes for special character escaping in Omnichannel. Also updates Node, Deno, MongoDB, and Apps-Engine engine versions.

Engine versions

  • Node: 22.16.0
  • Deno: 1.43.5
  • MongoDB: 8.0
  • Apps-Engine: 1.60.1

Patch Changes

securitypatchomnichannelauthenticationssrf

Source: original entry ↗