Image reports › rabbitmq
rabbitmq — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/rabbitmq · Ubuntu 24.04.5 LTS
Latest: rabbitmq:latest · checked 2026-09-25
Not FIPS-ready
No. rabbitmq:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 69 known vulnerabilities
69 known vulnerabilities in 8 packages (4 critical, 26 high); 62 can be fixed by upgrading 1 package. Start with stdlib: upgrade 1.22.2 → 1.25.13 (fixes 62).
Fix plan for latest
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.22.2 | 1.25.13 | 62 |
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | GO-2024-2887 | stdlib 1.22.2 | 1.22.4 | Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip |
| critical | GO-2026-5026 | stdlib 1.22.2 | 1.25.13 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| critical | GO-2025-3563 | stdlib 1.22.2 | 1.23.8 | Request smuggling due to acceptance of invalid chunked data in net/http |
| critical | GO-2026-4337 | stdlib 1.22.2 | 1.24.13 | Unexpected session resumption in crypto/tls |
| high | GO-2026-4970 | stdlib 1.22.2 | 1.25.12 | Root escape via symlink plus trailing slash in os |
| high | GO-2024-2963 | stdlib 1.22.2 | 1.22.5 | Denial of service due to improper 100-continue handling in net/http |
| high | GO-2024-3106 | stdlib 1.22.2 | 1.22.7 | Stack exhaustion in Decoder.Decode in encoding/gob |
| high | GO-2024-3107 | stdlib 1.22.2 | 1.22.7 | Stack exhaustion in Parse in go/build/constraint |
| high | GO-2025-4006 | stdlib 1.22.2 | 1.24.8 | Excessive CPU consumption in ParseAddress in net/mail |
| high | GO-2025-4007 | stdlib 1.22.2 | 1.24.9 | Quadratic complexity when checking name constraints in crypto/x509 |
| high | GO-2025-4009 | stdlib 1.22.2 | 1.24.8 | Quadratic complexity when parsing some invalid inputs in encoding/pem |
| high | GO-2025-4013 | stdlib 1.22.2 | 1.24.8 | Panic when validating certificates with DSA public keys in crypto/x509 |
| high | GO-2025-4155 | stdlib 1.22.2 | 1.24.11 | Excessive resource consumption when printing error string for host certificate validation in crypto/x509 |
| high | GO-2026-4341 | stdlib 1.22.2 | 1.24.12 | Memory exhaustion in query parameter parsing in net/url |
| high | GO-2026-4601 | stdlib 1.22.2 | 1.25.8 | Incorrect parsing of IPv6 host literals in net/url |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | F 69 4 critical | 2026-09-25 | Full report |