StackRadar

CVE-2026-44839

Medium

Advisory

Published 29 May 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
2 of 2
affected packages

RabbitMQ: Unsanitized vhost names allow for XSS in management UI

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
rabbitmqbitnami3.10.7-1, 3.10.8-1, 3.11.18-0, 3.12.14-10+2 more4.0.137
RabbitMQbitnami3.11.18, 3.12.14-104.0.132
OSV records
BIT-rabbitmq-2026-44839
Also known as
GHSA-fh5r-jpm3-fjwp

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
openctihelm-openctiVerified publisher3.0.91 of 8See more

opencti helm-opencti 3.0.9

1 of the 8 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
4.0.13

Open the chart page →

3,383
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:3.13.7-debian-12-r2cd593809e359
rabbitmq@3.13.7-0
4.0.13

Open the chart page →

52,635
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
rabbitmq@3.12.14-10
RabbitMQ@3.12.14-10
4.0.13
4.0.13

Open the chart page →

31,510
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
rabbitmq@3.10.8-1
4.0.13

Open the chart page →

37,373
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
rabbitmq@4.1.2-0
4.0.13

Open the chart page →

40,238
openaevhelm-openbasVerified publisher2.0.51 of 7See more

openaev helm-openbas 2.0.5

1 of the 7 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
4.0.13

Open the chart page →

7,437
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
4.0.13

Open the chart page →

25,017
ibm-ucv-prodibm-helm5.2.61 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

1 of the 16 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2fac502149c40
rabbitmq@4.1.2-0
4.0.13

Open the chart page →

12,105
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
rabbitmq@3.10.7-1
4.0.13

Open the chart page →

11,636
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-44839.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
rabbitmq@3.11.18-0
RabbitMQ@3.11.18
4.0.13
4.0.13

Open the chart page →

66,266

Container images carrying it

7 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
4.0.13
4
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
rabbitmq@3.11.18-0
RabbitMQ@3.11.18
4.0.13
4.0.13
1
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
rabbitmq@4.1.2-0
4.0.13
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
rabbitmq@3.10.8-1
4.0.13
1
bitnamilegacy/rabbitmq:3.13.7-debian-12-r2cd593809e359
rabbitmq@3.13.7-0
4.0.13
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
rabbitmq@3.10.7-1
4.0.13
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
rabbitmq@3.12.14-10
RabbitMQ@3.12.14-10
4.0.13
4.0.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.