๐Ÿ” CVE Alert

CVE-2026-30833

UNKNOWN 0.0

Rocket.Chat: NoSQL injection in the EE ddp-streamer-service

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in Rocket.Chat's account service used in the ddp-streamer micro service that allows unauthenticated attackers to manipulate MongoDB queries during authentication. The vulnerability is located in the username-based login flow where user-supplied input is directly embedded into a MongoDB query selector without validation. An attacker can inject MongoDB operator expressions (e.g., { $regex: '.*' }) in place of a username string, causing the database query to match unintended user records. This issue has been patched in versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0.

CWE CWE-943
Vendor rocketchat
Product rocket.chat
Published Mar 6, 2026
Last Updated Mar 9, 2026
Stay Ahead of the Next One

Get instant alerts for rocketchat rocket.chat

Be the first to know when new unknown vulnerabilities affecting rocketchat rocket.chat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

RocketChat / Rocket.Chat
< 7.10.8 < 7.11.5 < 7.12.5 < 7.13.4 < 8.0.2 < 8.1.1 < 8.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-hgq6-9jg2-wf3f