StackRadar

activemq Helm chart

microboxlabs

Scored 14 Sept 2026

A Helm chart providing a basic Apache ActiveMQ deployment required to evaluate ACS (not meant to be used in production).

Latest 3.8.0 7 months agoapp version 5.18.7 0Artifact Hub

activemq 3.8.0 deploys 1 container image: alfresco/alfresco-activemq. Across them, 98 findings2 critical, 3 high 2 on CISA KEV. The highest contribution is GHSA-rxpj-7qvf-xv32 in activemq-all 5.18.7, fixed in 5.19.5.

Radar Score

1,494232568

98 findings over 1 of 1 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
alfresco/alfresco-activemq5.18.7-jre17-rockylinux82325681,494

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

98 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-6hg6-v5c8-fphqlog4j-core@2.24.12.25.4
LowGHSA-72hv-8253-57qqjackson-core@2.18.22.18.6
LowGHSA-4xh5-x5gv-qwphpip@9.0.325.3
LowGHSA-5gvw-p9qm-jgwhjackson-databind@2.18.22.18.9
LowGHSA-h35f-9h28-mq5csetuptools@39.2.083.0.0
LowGHSA-4gc7-5j7h-4qphspring-web@5.3.39no fix listed
LowGHSA-4gc7-5j7h-4qphspring-context@5.3.39no fix listed
LowRLSA-2026:65998gzip@1.9-13.el8_50:1.9-15.el8_10
LowRLSA-2026:66451glib2@2.56.4-170.el8_100:2.56.4-178.el8_10
LowGHSA-3pjw-73gf-8qr5jackson-databind@2.18.22.18.8
LowGHSA-fcvm-3cpj-f9qxshiro-core@1.13.02.2.0
LowRLSA-2026:58938sqlite@3.26.0-20.el8_100:3.26.0-21.el8_10
LowPYSEC-2026-3721pip@9.0.326.2
LowGHSA-mq26-g339-26xfpip@9.0.323.3
LowGHSA-4773-3jfm-qmx3spring-webmvc@5.3.39no fix listed
LowGHSA-72pg-x5f8-j25jspring-webmvc@5.3.39no fix listed
LowGHSA-hf52-78x8-6w3wactivemq-all@5.18.75.19.7
LowGHSA-hf52-78x8-6w3wactivemq-broker@5.18.75.19.7
LowGHSA-mq64-j8f9-9gcjspring-webmvc@5.3.39no fix listed
LowGHSA-r7wm-3cxj-wff9jackson-core@2.18.22.18.8
LowRLSA-2026:64809expat@2.5.0-2.el8_100:2.5.0-2.el8_10.2
LowGHSA-3chg-m5w7-qfv5spring-webmvc@5.3.39no fix listed
LowGHSA-hgj6-7826-r7m5jackson-databind@2.18.22.18.8
LowGHSA-wxpp-56q6-5pcgspring-expression@5.3.39no fix listed
LowGHSA-c244-p6m5-vqj6shiro-spring@1.13.02.1.0
LowGHSA-5jmj-h7xm-6q6vjackson-databind@2.18.22.18.9
LowGHSA-6p4f-wcwh-5vvmspring-webmvc@5.3.39no fix listed
LowGHSA-qh8g-58pp-2wxhjetty-http@9.4.57.v2024121912.0.12
LowGHSA-7p3p-8qv8-m2vhjetty-server@9.4.57.v20241219no fix listed
LowGHSA-h2h4-5m64-m273activemq-web@5.18.75.19.3
LowGHSA-h2h4-5m64-m273activemq-broker@5.18.75.19.3
LowGHSA-h2h4-5m64-m273activemq-client@5.18.75.19.3
LowGHSA-h2h4-5m64-m273activemq-all@5.18.75.19.3
LowGHSA-957g-f97v-vppcspring-webmvc@5.3.39no fix listed
LowGHSA-cjpg-rgq5-fr37spring-webmvc@5.3.39no fix listed
LowGHSA-mhm7-754m-9p8wjackson-databind@2.18.22.18.9
LowGHSA-jp4c-xjxw-mgf9pip@9.0.326.1
LowRLSA-2026:61248libxml2@2.9.7-21.el8_10.60:2.9.7-21.el8_10.7
LowGHSA-659m-px2c-25wjspring-core@5.3.39no fix listed
LowGHSA-58qw-9mgm-455vpip@9.0.326.1
LowGHSA-4wp7-92pw-q264spring-context@5.3.39no fix listed
LowGHSA-h3qp-gqrc-q736spring-webmvc@5.3.39no fix listed
LowGHSA-9f52-rjqv-25qvspring-expression@5.3.39no fix listed
LowGHSA-wjpw-4j6x-6rwhjetty-http@9.4.57.v20241219no fix listed
LowGHSA-wg35-8jpf-2xv3spring-webmvc@5.3.39no fix listed
LowGHSA-6vgw-5pg2-w6jppip@9.0.326.0
LowGHSA-6hcq-hmm3-jj3cspring-webmvc@5.3.39no fix listed
LowGHSA-c4qc-4q9p-m9q9shiro-core@1.13.02.1.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.8.0latest7 months ago5.18.72325681,494

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/microboxlabs/activemq.svg)](https://charts.stackradar.io/charts/microboxlabs/activemq)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.