Where
-Infinity
0

Vendor Risk Score

See how argoproj compares to other vendors in security performance

View Risk Score →

argoproj Argo Workflows GoArgo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencing

Risk 82
Severity
8.9
First published (updated )

go/github.com/argoproj/argo-cd/v3Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

Risk 61
Severity
8.7
First published (updated )

go/github.com/argoproj/argo-cd/v3Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations

Risk 38
Severity
6.5
First published (updated )

go/github.com/argoproj/argo-cd/v3ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

Risk 68
Severity
9.6
First published (updated )

go/github.com/argoproj/argo-workflows/v4Argo Workflows: Exposure of artifact repository credentials

Risk 57
Severity
8.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

argoproj Argo Workflows GoArgo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure

Risk 60
Severity
8.1
First published (updated )

argoproj Argo Workflows GoArgo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

Risk 43
Severity
8.2
First published (updated )

go/github.com/argoproj/argo-workflows/v4Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

Risk 38
Severity
2.3
First published (updated )

go/github.com/argoproj/argo-workflows/v4Argo Workflows Is Missing Authorization in Sync ConfigMap Provider

Risk 70
Severity
8.5
First published (updated )

argoproj Argo Workflows GoArgo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller

Risk 44
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

argoproj Argo Workflows GoWorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode

Risk 59
Severity
8.9
EPSS
0.03%
First published (updated )

argoproj Argo Workflows GoArgo Workflows has unauthorized access to Argo Workflows Template

Risk 86
Severity
9.8
First published (updated )

go/github.com/argoproj/argo-workflows/v3Argo Workflows affected by stored XSS in the artifact directory listing

Risk 51
Severity
7.3
EPSS
0.05%
First published (updated )

go/github.com/argoproj/argo-workflows/v3argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links

Risk 60
Severity
8.1
First published (updated )

go/github.com/argoproj/argo-workflows/v3Argo Workflows exposes artifact repository credentials in workflow-controller logs

Risk 57
Severity
8.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/argoproj/argo-workflows/v3argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite

Risk 79
Severity
8.8
First published (updated )

argoproj Argo CDArgo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook

Risk 46
Severity
7.5
First published (updated )

argoproj Argo CDargo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payload

Risk 43
Severity
7.5
First published (updated )

argoproj Argo CDUnauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload

Risk 46
Severity
7.5
First published (updated )

argoproj Argo CDRepository Credentials Race Condition Crashes Argo CD Server

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

argoproj Argo CDArgo CD: Project API Token Exposes Repository Credentials

Risk 87
Severity
10
First published (updated )

argoproj Argo CDArgo CD allows cross-site scripting on repositories page

Risk 55
Severity
9.1
EPSS
0.04%
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD does not scrub secret values from patch errors

Risk 27
Severity
6.8
EPSS
0.04%
First published (updated )

go/github.com/argoproj/argo-workflows/v3Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode

Risk 45
Severity
7.5
First published (updated )

go/github.com/argoproj/argo-workflows/v3Argo Workflows Controller: Denial of Service via malicious daemon Workflows

Risk 35
Severity
5.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/argoproj/argo-cd/v2The Argo CD web terminal session does not handle the revocation of user permissions properly.

Risk 40
Severity
6.5
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint

Risk 45
Severity
7.5
First published (updated )

go/github.com/argoproj/argo-cd/v2/serverUnauthenticated Access to sensitive settings in Argo CD

Risk 45
Severity
7.5
First published (updated )

go/github.com/argoproj/argo-cdArgo CD allows authenticated users to enumerate clusters by name

Risk 23
Severity
4.3
First published (updated )

go/github.com/argoproj/argo-cd/v2ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache

Risk 80
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203