OCImendby CloudTrace

Image reports › docker.io/ubuntu/rabbitmq

docker.io/ubuntu/rabbitmq — vulnerabilities, FIPS 140-3 and fixes

docker.io/ubuntu/rabbitmq · Ubuntu 26.04.1 LTS

Latest: docker.io/ubuntu/rabbitmq:4.0-26.04_stable · checked 2026-09-28

Not FIPS-ready

No. rabbitmq:4.0-26.04_stable relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade F: 941 known vulnerabilities

941 known vulnerabilities in 30 packages (17 critical, 224 high); 1 can be fixed by upgrading 1 package. Start with coreutils: upgrade 9.5-1ubuntu2+0.0.0~ubuntu25 → 9.7-3ubuntu2.1 (fixes 1).

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for 4.0-26.04_stable

PackageInstalledUpgrade toFixes
coreutils9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.11

Critical, high and exploited vulnerabilities in 4.0-26.04_stable

SeverityIDPackageFixed inSummary
criticalUBUNTU-CVE-2026-23941erlang-asn1 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-base 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-crypto 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-eldap 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-ftp 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-inets 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-mnesia 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-os-mon 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-parsetools 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-public-key 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-runtime-tools 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-snmp 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-ssl 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-syntax-tools 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.
criticalUBUNTU-CVE-2026-23941erlang-tftp 1:27.3.4.6+dfsg-1no fix yetInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.

All checked tags

TagFIPSKnown vulnerabilitiesChecked
4.0-26.04_stableNot FIPS-readyF 941 17 critical2026-09-28ReportFix