Image reports › docker.io/ubuntu/rabbitmq
docker.io/ubuntu/rabbitmq — vulnerabilities, FIPS 140-3 and fixes
docker.io/ubuntu/rabbitmq · Ubuntu 26.04.1 LTS
Latest: docker.io/ubuntu/rabbitmq:4.0-26.04_stable · checked 2026-09-28
Not FIPS-ready
No. rabbitmq:4.0-26.04_stable relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade F: 941 known vulnerabilities
941 known vulnerabilities in 30 packages (17 critical, 224 high); 1 can be fixed by upgrading 1 package. Start with coreutils: upgrade 9.5-1ubuntu2+0.0.0~ubuntu25 → 9.7-3ubuntu2.1 (fixes 1).
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for 4.0-26.04_stable
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | 9.7-3ubuntu2.1 | 1 |
Critical, high and exploited vulnerabilities in 4.0-26.04_stable
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | UBUNTU-CVE-2026-23941 | erlang-asn1 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-base 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-crypto 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-eldap 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-ftp 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-inets 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-mnesia 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-os-mon 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-parsetools 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-public-key 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-runtime-tools 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-snmp 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-ssl 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-syntax-tools 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
| critical | UBUNTU-CVE-2026-23941 | erlang-tftp 1:27.3.4.6+dfsg-1 | no fix yet | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 4.0-26.04_stable | Not FIPS-ready | F 941 17 critical | 2026-09-28 | ReportFix |