argoproj
Cloud & SaaSoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting argoproj.
- CVE-2026-54526Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencing9.9
- CVE-2026-45737Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations6.3
- CVE-2026-45738Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation7.3
- CVE-2026-15416Argo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpoint8.9
- CVE-2026-62185Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE7.6
- CVE-2026-42296Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure8.1
- CVE-2026-42295Argo Workflows: Exposure of artifact repository credentials4.9
- CVE-2026-42294Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor7.5
- CVE-2026-42183Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)6.5
- CVE-2026-42297Argo Workflows Is Missing Authorization in Sync ConfigMap Provider8.3
- CVE-2026-42880ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction9.6
- CVE-2026-43824In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.7.7
- CVE-2026-40886Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller7.7
- CVE-2026-31892WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode8.1
- CVE-2026-28229Argo Workflows has unauthorized access to Argo Workflows Template9.8