StackRadar

CVE-2026-67230

Medium

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,985 indexed, latest versions
Container images
3
deployed by those charts
Fix available
1 of 1
affected package

RabbitMQ: Web-STOMP unbounded pre-auth accumulation

Carried by container images the latest versions of 11 of 17,985 indexed charts deploy, on 3 images.

Affected packageAffected versionsFixed inImages
rabbitmqbitnami4.1.2-0, 4.1.3-03.13.153
OSV records
BIT-rabbitmq-2026-67230

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
codefreshcodefresh-onpremOfficialVerified publisher2.12.191See more

codefresh codefresh-onprem 2.12.19

1 container image this version deploys carries CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.39e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

—
openctihelm-openctiVerified publisher3.0.141See more

opencti helm-opencti 3.0.14

1 container image this version deploys carries CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

—
infrahubinfrahubVerified publisher4.33.41See more

infrahub infrahub 4.33.4

1 container image this version deploys carries CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

—
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.21.11See more

infrahub-enterprise infrahub-enterprise 4.21.1

1 container image this version deploys carries CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

—
squestchristianhuthVerified publisher6.6.81 of 4See more

squest christianhuth 6.6.8

1 of the 4 container images this version deploys carry CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

11,073
arlas-aiasarlas-stackVerified publisher28.9.01 of 22See more

arlas-aias arlas-stack 28.9.0

1 of the 22 container images this version deploys carry CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

42,910
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

7,921
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15

Open the chart page →

7,921
openaevhelm-openbasVerified publisher2.0.81 of 7See more

openaev helm-openbas 2.0.8

1 of the 7 container images this version deploys carry CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

7,757
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

27,052
ibm-ucv-prodibm-helm5.3.01 of 16See more

ibm-ucv-prod ibm-helm 5.3.0

1 of the 16 container images this version deploys carry CVE-2026-67230.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2fac502149c40
rabbitmq@4.1.2-0
3.13.15

Open the chart page →

12,575

Container images carrying it

3 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
rabbitmq@4.1.3-0
3.13.15
6
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
rabbitmq@4.1.2-0
3.13.15
4
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
rabbitmq@4.1.2-0
3.13.15
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.