{"api_version":"v1","generated_at":"2026-10-07T20:00:00+00:00","product":{"cve_count":13,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-rocket-chat-rocket-chat-8ef5d32d3b3b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/rocket.chat","name":"rocket.chat","next_cursor":null,"observations":[{"affected":"< 8.8.0; < 8.7.1; < 8.6.2; < 8.5.3; < 8.4.6; < 8.3.8; < 8.2.8; < 8.1.8","affected_versions_present":true,"cve_id":"CVE-2026-65644","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65644","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-27T19:19:36.705Z","patch_url":"https://github.com/RocketChat/Rocket.Chat/pull/41595","primary_source":"","published":"2026-08-21T02:53:43.406Z"},{"affected":"< 8.8.0; < 8.7.1; < 8.6.2; < 8.5.3; < 8.4.6; < 8.3.8; < 8.2.8; < 8.1.8","affected_versions_present":true,"cve_id":"CVE-2026-65645","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65645","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-27T17:46:35.706Z","patch_url":"https://github.com/RocketChat/Rocket.Chat/pull/41814","primary_source":"","published":"2026-08-21T02:53:43.305Z"},{"affected":"< 8.2.0; < 8.1.1; < 8.0.2; < 7.13.4; < 7.12.5; < 7.11.5; < 7.10.8","affected_versions_present":true,"cve_id":"CVE-2026-56845","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56845","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-04T15:04:12.768Z","patch_url":"","primary_source":"","published":"2026-08-04T00:43:48.076Z"},{"affected":"< 8.7.0; < 8.6.1; < 8.5.2; < 8.4.5; < 8.3.7; < 8.2.7; < 8.1.7; < 8.0.8","affected_versions_present":true,"cve_id":"CVE-2026-58066","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58066","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-31T03:55:47.931Z","patch_url":"","primary_source":"","published":"2026-07-30T06:03:45.178Z"},{"affected":"< 8.5.1; < 8.4.4; < 8.3.6; < 8.2.6; < 8.1.6; < 8.0.7; < 7.13.9; < 7.10.13","affected_versions_present":true,"cve_id":"CVE-2026-48616","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48616","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-17T15:01:42.246Z","patch_url":"https://github.com/RocketChat/Rocket.Chat/pull/40889","primary_source":"","published":"2026-06-16T23:08:37.908Z"},{"affected":"< 8.5.1; < 8.4.4; < 8.3.6; < 8.2.6; < 8.1.6; < 8.0.7; < 7.13.9; < 7.10.13","affected_versions_present":true,"cve_id":"CVE-2026-48929","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48929","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-17T15:02:44.803Z","patch_url":"https://github.com/RocketChat/Rocket.Chat/pull/40889/","primary_source":"","published":"2026-06-16T23:08:37.888Z"},{"affected":"8.5.0 < 8.5.0; 8.4.0 < 8.4.2; 8.3.0 < 8.3.4; 8.2.0 < 8.2.4; 8.1.0 < 8.1.5; 8.0.0 < 8.0.6; 7.13.0 < 7.13.8; 7.10.0 < 7.10.12","affected_versions_present":true,"cve_id":"CVE-2026-32995","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32995","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T13:13:36.583Z","patch_url":"","primary_source":"","published":"2026-05-28T04:01:37.645Z"},{"affected":"< 8.5.0; < 8.4.2; < 8.3.4; < 8.2.4; < 8.1.5; < 8.0.6; < 7.13.8; < 7.10.12","affected_versions_present":true,"cve_id":"CVE-2026-32994","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32994","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-19T12:36:27.839Z","patch_url":"","primary_source":"","published":"2026-05-19T04:43:41.777Z"},{"affected":"8.4.0 < 8.4.0; 8.3.2 < 8.3.2; 8.2.2 < 8.2.2; 8.1.3 < 8.1.3; 8.0.4 < 8.0.4; 7.13.6 < 7.13.6; 7.12.7 < 7.12.7; 7.11.7 < 7.11.7","affected_versions_present":true,"cve_id":"CVE-2026-29197","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29197","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-24T14:18:07.117Z","patch_url":"https://github.com/RocketChat/Rocket.Chat/pull/40125","primary_source":"","published":"2026-04-23T23:19:40.722Z"},{"affected":"See the vendor and CVE records for the affected range.","affected_versions_present":false,"cve_id":"CVE-2026-29198","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29198","fixed":"8.3.0 < 8.3.0; 8.2.1 < 8.2.1; 8.0.3 < 8.0.3; 7.13.5 < 7.13.5; 7.12.6 < 7.12.6; 7.11.6 < 7.11.6; 7.10.9 < 7.10.9","last_modified":"2026-04-23T17:41:50.981Z","patch_url":"https://github.com/RocketChat/Rocket.Chat/pull/39492","primary_source":"","published":"2026-04-22T23:30:15.355Z"},{"affected":"8.4.0 < 8.4.0","affected_versions_present":true,"cve_id":"CVE-2026-22560","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22560","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-14T19:04:32.571Z","patch_url":"","primary_source":"","published":"2026-04-10T17:00:11.746Z"},{"affected":"7.3.1","affected_versions_present":true,"cve_id":"CVE-2025-7974","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-7974","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-03T20:06:25.162Z","patch_url":"","primary_source":"","published":"2025-09-02T19:46:21.117Z"},{"affected":"6.10.1 < 6.10.1","affected_versions_present":true,"cve_id":"CVE-2024-39713","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-39713","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-06T16:32:07.303Z","patch_url":"","primary_source":"","published":"2024-08-05T04:26:06.959Z"},{"affected":"6.10.0 < 6.10.0","affected_versions_present":true,"cve_id":"CVE-2024-37405","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-37405","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T03:50:56.177Z","patch_url":"","primary_source":"","published":"2024-07-12T15:41:03.461Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"rocket.chat"}}
