vciy

CVEs we hold for Argoproj

Records whose assigning authority named Argoproj as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-82456argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTPargoproj-labs argocd-mcp
CVE-2026-82277Argo Rollouts Dashboard Unauthenticated Mutating Operationsargoproj argo-rollouts
CVE-2026-62185Argo CD Helm Chart < 10.0.0 Missing Network Policy RCEargoproj argo-helm
CVE-2026-54526Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencingargoproj argo-workflows
CVE-2026-45738Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalationargoproj argo-cd
CVE-2026-45737Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotationsargoproj argo-cd
CVE-2026-43824no title heldargoproj Argo CD
CVE-2026-42880ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extractionargoproj argo-cd
CVE-2026-42297Argo Workflows Is Missing Authorization in Sync ConfigMap Providerargoproj argo-workflows
CVE-2026-42296Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass…argoproj argo-workflows
CVE-2026-42295Argo Workflows: Exposure of artifact repository credentialsargoproj argo-workflows
CVE-2026-42294Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptorargoproj argo-workflows
CVE-2026-42183Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)argoproj argo-workflows
CVE-2026-40886Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controllerargoproj argo-workflows
CVE-2026-31892WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Modeargoproj argo-workflows
CVE-2026-28229Argo Workflows has unauthorized access to Argo Workflows Templateargoproj argo-workflows
CVE-2026-23960Argo Workflows affected by stored XSS in the artifact directory listingargoproj argo-workflows
CVE-2026-15416Argo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpointargoproj argo-helm; Red Hat OpenShift GitOps 1.19…
CVE-2025-66626argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic linksargoproj argo-workflows
CVE-2025-62157Argo Workflows exposes artifact repository credentials in workflow-controller logsargoproj argo-workflows
CVE-2025-62156argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwriteargoproj argo-workflows
CVE-2025-59538Argo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhookargoproj argo-cd
CVE-2025-59537argo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payloadargoproj argo-cd
CVE-2025-59531Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payloadargoproj argo-cd
CVE-2025-55191Repository Credentials Race Condition Crashes Argo CD Serverargoproj argo-cd
CVE-2025-55190Argo CD: Project API Token Exposes Repository Credentialsargoproj argo-cd
CVE-2025-47933Argo CD allows cross-site scripting on repositories pageargoproj argo-cd
CVE-2025-32445Users can gain privileged access to the host system and cluster with EventSource and Sensor CRargoproj argo-events
CVE-2025-23216Argo CD does not scrub secret values from patch errorsargoproj argo-cd
CVE-2024-53862Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` modeargoproj argo-workflows
CVE-2024-52814Helm Lacks Granularity in Workflow Roleargoproj argo-helm
CVE-2024-52799Argo Workflows Chart: Excessive Privileges in Workflow Roleargoproj argo-helm
CVE-2024-47827Argo Workflows Controller: Denial of Service via malicious daemon Workflowsargoproj argo-workflows
CVE-2024-41666The Argo CD web terminal session does not handle the revocation of user permissions properly.argoproj argo-cd
CVE-2024-40634Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpointargoproj argo-cd
CVE-2024-37152Unauthenticated Access to sensitive settings in Argo CDargoproj argo-cd
CVE-2024-36106Argo CD allows authenticated users to enumerate clusters by nameargoproj argo-cd
CVE-2024-32476Denial of Service via malicious jqPathExpressions in ignoreDifferencesargoproj argo-cd
CVE-2024-31990Argo CD' API server does not enforce project sourceNamespacesargoproj argo-cd
CVE-2024-31989ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cacheargoproj argo-cd
CVE-2024-29893Uncontrolled Resource Consumption vulnerability in ArgoCD's repo serverargoproj argo-cd
CVE-2024-28175Cross-site scripting on application summary component in argo-cdargoproj argo-cd
CVE-2024-22424Cross-Site Request Forgery (CSRF) in github.com/argoproj/argo-cdargoproj argo-cd
CVE-2024-21662Argo CD vulnerable to Bypassing of Rate Limit and Brute Force Protection Using Cache Overflowargoproj argo-cd
CVE-2024-21661Argo CD Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environmentargoproj argo-cd
CVE-2024-21652Argo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data Lossargoproj argo-cd
CVE-2023-50726Users with `create` but not `override` privileges can perform local sync in argo-cdargoproj argo-cd
CVE-2023-40584Denial of Service to Argo CD repo-serverargoproj argo-cd
CVE-2023-40029Cluster secret might leak in cluster details page in Argo CDargoproj argo-cd
CVE-2023-40026Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-serverargoproj argo-cd
CVE-2023-40025Argo CD web terminal session doesn't expireargoproj argo-cd
CVE-2023-25163Argo CD leaks repository credentials in user-facing error messages and in logsargoproj argo-cd
CVE-2023-23947Argo CD users with any cluster secret update access may update out-of-bounds cluster secretsargoproj argo-cd
CVE-2023-22736argo-cd Controller reconciles apps outside configured namespaces when sharding is enabledargoproj argo-cd
CVE-2023-22482JWT audience claim is not verifiedargoproj argo-cd
CVE-2022-31105Argo CD's certificate verification is skipped for connections to OIDC providersargoproj argo-cd
CVE-2022-31102Cross-site Scripting for Argo CD single sign on usersargoproj argo-cd
CVE-2022-31054Uses of deprecated API can be used to cause DoS in user-facing endpoints in Argo Eventsargoproj argo-events
CVE-2022-31036Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-serverargoproj argo-cd
CVE-2022-31035External URLs for Deployments can include javascript in argo-cdargoproj argo-cd
CVE-2022-31034Insecure entropy in argo-cdargoproj argo-cd
CVE-2022-31016Argo CD vulnerable to Uncontrolled Memory Consumptionargoproj argo-cd
CVE-2022-29165Argo CD will blindly trust JWT claims if anonymous access is enabledargoproj argo-cd
CVE-2022-29164Privilege Escalation in argo-workflowsargoproj argo-workflows
CVE-2022-24905Argo CD login screen allows message spoofing if SSO is enabledargoproj argo-cd
CVE-2022-24904Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-serverargoproj argo-cd
CVE-2022-24768Improper access control allows admin privilege escalation in Argo CDargoproj argo-cd
CVE-2022-24731Path traversal allows leaking out-of-bound files from Argo CD repo-serverargoproj argo-cd
CVE-2022-24730Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-serverargoproj argo-cd

69 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.