megachangelog
Security8.3.8

Rocket.Chat 8.3.8

Patch release with security fixes including per-client rate limiting for forgot password endpoint, SSRF protection in file downloads, and fixes for special character escaping in Omnichannel visitor names.

Engine versions

  • Node: 22.16.0
  • Deno: 1.43.5
  • MongoDB: 8.0
  • Apps-Engine: 1.61.1

Patch Changes

securityrate-limitingomnichannelpatch

Source: original entry ↗