CVEs we hold for Argoproj
Records whose assigning authority named Argoproj as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-82456argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTPargoproj-labs argocd-mcp
CVE-2026-54526Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencingargoproj argo-workflows
CVE-2026-45738Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalationargoproj argo-cd
CVE-2026-45737Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotationsargoproj argo-cd
CVE-2026-42297Argo Workflows Is Missing Authorization in Sync ConfigMap Providerargoproj argo-workflows
CVE-2026-42296Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass…argoproj argo-workflows
CVE-2026-42294Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptorargoproj argo-workflows
CVE-2026-42183Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)argoproj argo-workflows
CVE-2026-40886Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controllerargoproj argo-workflows
CVE-2026-31892WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Modeargoproj argo-workflows
CVE-2026-28229Argo Workflows has unauthorized access to Argo Workflows Templateargoproj argo-workflows
CVE-2026-23960Argo Workflows affected by stored XSS in the artifact directory listingargoproj argo-workflows
CVE-2026-15416Argo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpointargoproj argo-helm; Red Hat OpenShift GitOps 1.19…
CVE-2025-66626argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic linksargoproj argo-workflows
CVE-2025-62157Argo Workflows exposes artifact repository credentials in workflow-controller logsargoproj argo-workflows
CVE-2025-62156argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwriteargoproj argo-workflows
CVE-2025-59538Argo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhookargoproj argo-cd
CVE-2025-59537argo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payloadargoproj argo-cd
CVE-2025-59531Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payloadargoproj argo-cd
CVE-2025-32445Users can gain privileged access to the host system and cluster with EventSource and Sensor CRargoproj argo-events
CVE-2024-53862Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` modeargoproj argo-workflows
CVE-2024-47827Argo Workflows Controller: Denial of Service via malicious daemon Workflowsargoproj argo-workflows
CVE-2024-41666The Argo CD web terminal session does not handle the revocation of user permissions properly.argoproj argo-cd
CVE-2024-40634Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpointargoproj argo-cd
CVE-2024-32476Denial of Service via malicious jqPathExpressions in ignoreDifferencesargoproj argo-cd
CVE-2024-31989ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cacheargoproj argo-cd
CVE-2024-29893Uncontrolled Resource Consumption vulnerability in ArgoCD's repo serverargoproj argo-cd
CVE-2024-21662Argo CD vulnerable to Bypassing of Rate Limit and Brute Force Protection Using Cache Overflowargoproj argo-cd
CVE-2024-21661Argo CD Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environmentargoproj argo-cd
CVE-2024-21652Argo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data Lossargoproj argo-cd
CVE-2023-50726Users with `create` but not `override` privileges can perform local sync in argo-cdargoproj argo-cd
CVE-2023-40026Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-serverargoproj argo-cd
CVE-2023-25163Argo CD leaks repository credentials in user-facing error messages and in logsargoproj argo-cd
CVE-2023-23947Argo CD users with any cluster secret update access may update out-of-bounds cluster secretsargoproj argo-cd
CVE-2023-22736argo-cd Controller reconciles apps outside configured namespaces when sharding is enabledargoproj argo-cd
CVE-2022-31105Argo CD's certificate verification is skipped for connections to OIDC providersargoproj argo-cd
CVE-2022-31054Uses of deprecated API can be used to cause DoS in user-facing endpoints in Argo Eventsargoproj argo-events
CVE-2022-31036Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-serverargoproj argo-cd
CVE-2022-24904Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-serverargoproj argo-cd
CVE-2022-24731Path traversal allows leaking out-of-bound files from Argo CD repo-serverargoproj argo-cd
CVE-2022-24730Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-serverargoproj argo-cd
69 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.