CVE-2024-46935: Rocket.chat

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.

Affected products

  • Rocket.chat Rocket.chat: before 6.7.9 (fixed in 6.7.9); from 6.8.0, before 6.8.7 (fixed in 6.8.7); from 6.9.0, before 6.9.7 (fixed in 6.9.7); from 6.10.0, before 6.10.6 (fixed in 6.10.6); from 6.11.0, before 6.11.3 (fixed in 6.11.3); version 6.12.0 only

Published 2024-09-25. Last modified 2026-06-17.