OCImendby CloudTrace

Image reports › rabbitmq

rabbitmq — vulnerabilities, FIPS 140-3 and fixes

docker.io/library/rabbitmq · Ubuntu 24.04.5 LTS

Latest: rabbitmq:4 · checked 2026-09-28

Not FIPS-ready

No. rabbitmq:4 relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade F: 69 known vulnerabilities

69 known vulnerabilities in 8 packages (4 critical, 27 high); 62 can be fixed by upgrading 1 package. Start with stdlib: upgrade 1.22.2 → 1.25.13 (fixes 62).

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for 4

PackageInstalledUpgrade toFixes
stdlib1.22.21.25.1362

Critical, high and exploited vulnerabilities in 4

SeverityIDPackageFixed inSummary
criticalGO-2024-2887stdlib 1.22.21.22.4Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
criticalGO-2026-4337stdlib 1.22.21.24.13Unexpected session resumption in crypto/tls
criticalGO-2025-3563stdlib 1.22.21.23.8Request smuggling due to acceptance of invalid chunked data in net/http
criticalGO-2026-5026stdlib 1.22.21.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
highGO-2026-4341stdlib 1.22.21.24.12Memory exhaustion in query parameter parsing in net/url
highUBUNTU-CVE-2016-20013libc6 2.39-0ubuntu8.9no fix yetsha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.
highGO-2024-3106stdlib 1.22.21.22.7Stack exhaustion in Decoder.Decode in encoding/gob
highGO-2024-2963stdlib 1.22.21.22.5Denial of service due to improper 100-continue handling in net/http
highGO-2024-3107stdlib 1.22.21.22.7Stack exhaustion in Parse in go/build/constraint
highGO-2026-4981stdlib 1.22.21.25.10Crash when handling long CNAME response in net
highGO-2026-4986stdlib 1.22.21.25.10Quadratic string concatentation in consumeComment in net/mail
highGO-2026-4601stdlib 1.22.21.25.8Incorrect parsing of IPv6 host literals in net/url
highGO-2026-4977stdlib 1.22.21.25.10Quadratic string concatenation in consumePhrase in net/mail
highGO-2026-4918stdlib 1.22.21.25.10Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
highGO-2026-4947stdlib 1.22.21.25.9Unexpected work during chain building in crypto/x509

All checked tags

TagFIPSKnown vulnerabilitiesChecked
4Not FIPS-readyF 69 4 critical2026-09-28ReportFix
4-management-alpineNot FIPS-readyA 02026-09-28ReportFix
4.0-alpineNot FIPS-readyA 02026-09-28ReportFix
4.0Not FIPS-readyF 69 4 critical2026-09-28ReportFix