StackRadar

CVE-2026-33227

Medium

Advisory

Published 7 Apr 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
4 of 4
affected packages

Apache ActiveMQ: Improper validation and restriction of a classpath path name

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
activemq-clientmaven5.13.4, 5.14.5, 5.15.10, 5.15.12+6 more5.19.3, 6.2.212
activemq-brokermaven5.13.4, 5.17.3, 5.18.7, 6.1.65.19.3, 6.2.25
activemq-allmaven5.17.3, 5.18.75.19.32
activemq-webmaven5.17.3, 5.18.75.19.32
OSV records
GHSA-h2h4-5m64-m273
Also known as
BIT-activemq-2026-33227

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.21.060c3970df479
activemq-client@5.15.12
5.19.3

Open the chart page →

3,229
zipkinygqygq2Verified publisher2.1.41 of 4See more

zipkin ygqygq2 2.1.4

1 of the 4 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.24197a9692f6a9
activemq-client@5.18.3
5.19.3

Open the chart page →

2,764
activemq-artemisactivemq-artemis-helm0.3.61 of 1See more

activemq-artemis activemq-artemis-helm 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
vromero/activemq-artemis:2.16.0408d6a46b153
activemq-client@5.14.5
5.19.3

Open the chart page →

4,419
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
activemq-client@5.19.1
5.19.3

Open the chart page →

3,188
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
activemq-broker@6.1.6
activemq-client@6.1.6
6.2.2
6.2.2

Open the chart page →

3,963
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:latest536358d7b17e
activemq-broker@6.1.6
activemq-client@6.1.6
6.2.2
6.2.2

Open the chart page →

15,573
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
activemq-client@5.18.5
5.19.3

Open the chart page →

12,454
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
activemq-client@6.1.6
6.2.2

Open the chart page →

7,792
my-chartfleet-web-app0.1.03 of 6See more

my-chart fleet-web-app 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-position-simulator:release20b540a28f5a6
activemq-broker@5.13.4
activemq-client@5.13.4
5.19.3
5.19.3
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
activemq-broker@5.13.4
activemq-client@5.13.4
5.19.3
5.19.3
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
activemq-all@5.17.3
activemq-broker@5.17.3
activemq-client@5.17.3
activemq-web@5.17.3
5.19.3
5.19.3
5.19.3
5.19.3

Open the chart page →

24,296
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
activemq-all@5.18.7
activemq-broker@5.18.7
activemq-client@5.18.7
activemq-web@5.18.7
5.19.3
5.19.3
5.19.3
5.19.3

Open the chart page →

1,494
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
activemq-client@6.1.6
6.2.2

Open the chart page →

7,792
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33227.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
activemq-client@5.15.10
5.19.3

Open the chart page →

4,538

Container images carrying it

12 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
apache/fineract:1.12.1a83cf1980609
activemq-client@6.1.6
6.2.2
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
activemq-broker@6.1.6
activemq-client@6.1.6
6.2.2
6.2.2
2
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
activemq-all@5.18.7
activemq-broker@5.18.7
activemq-client@5.18.7
activemq-web@5.18.7
5.19.3
5.19.3
5.19.3
5.19.3
1
apache/activemq-artemis:2.44.00305c26f19ed
activemq-client@5.19.1
5.19.3
1
apache/activemq-artemis:2.37.0bae523439ee3
activemq-client@5.18.5
5.19.3
1
openzipkin/zipkin:2.24197a9692f6a9
activemq-client@5.18.3
5.19.3
1
openzipkin/zipkin:2.21.060c3970df479
activemq-client@5.15.12
5.19.3
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
activemq-client@5.15.10
5.19.3
1
richardchesterwood/k8s-fleetman-position-simulator:release20b540a28f5a6
activemq-broker@5.13.4
activemq-client@5.13.4
5.19.3
5.19.3
1
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
activemq-broker@5.13.4
activemq-client@5.13.4
5.19.3
5.19.3
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
activemq-all@5.17.3
activemq-broker@5.17.3
activemq-client@5.17.3
activemq-web@5.17.3
5.19.3
5.19.3
5.19.3
5.19.3
1
vromero/activemq-artemis:2.16.0408d6a46b153
activemq-client@5.14.5
5.19.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.