StackRadar

CVE-2026-66074

Medium

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
Medium
worst across findings
CVSS
6.0
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,985 indexed, latest versions
Container images
5
deployed by those charts
Fix available
1 of 1
affected package

RabbitMQ: ReDoS via management API ?name= filter

Carried by container images the latest versions of 13 of 17,985 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
rabbitmqbitnami3.13.7-0, 4.1.2-0, 4.1.3-0, 4.2.2-03.13.155
OSV records
BIT-rabbitmq-2026-66074
Also known as
GHSA-rg5q-vcgf-rfh7

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
codefreshcodefresh-onpremOfficialVerified publisher2.12.191See more

codefresh codefresh-onprem 2.12.19

1 container image this version deploys carries CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.39e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

—
openctihelm-openctiVerified publisher3.0.141See more

opencti helm-opencti 3.0.14

1 container image this version deploys carries CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

—
infrahubinfrahubVerified publisher4.33.41See more

infrahub infrahub 4.33.4

1 container image this version deploys carries CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

—
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.21.11See more

infrahub-enterprise infrahub-enterprise 4.21.1

1 container image this version deploys carries CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

—
squestchristianhuthVerified publisher6.6.81 of 4See more

squest christianhuth 6.6.8

1 of the 4 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

11,073
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:3.13.7-debian-12-r2cd593809e359
rabbitmq@3.13.7-0
3.13.15

Open the chart page →

56,801
arlas-aiasarlas-stackVerified publisher28.9.01 of 22See more

arlas-aias arlas-stack 28.9.0

1 of the 22 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

42,910
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

7,921
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

7,921
openaevhelm-openbasVerified publisher2.0.81 of 7See more

openaev helm-openbas 2.0.8

1 of the 7 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

7,757
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

27,052
ibm-ucv-prodibm-helm5.3.01 of 16See more

ibm-ucv-prod ibm-helm 5.3.0

1 of the 16 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2fac502149c40
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

12,575
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-66074.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
rabbitmq@4.2.2-0
3.13.15

Open the chart page →

2,698

Container images carrying it

5 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15
6
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
3.13.15
4
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
rabbitmq@4.1.2-0
3.13.15
1
bitnamilegacy/rabbitmq:3.13.7-debian-12-r2cd593809e359
rabbitmq@3.13.7-0
3.13.15
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
rabbitmq@4.2.2-0
3.13.15
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.