github.com/argoproj/argo-cd
Declarative Continuous Deployment for Kubernetes
Activity
- Latest release
- 5y ago
- Total releases
- 20
- Cadence
- ~6 days
- Last 12 months
- 0
Reach
- Stars
- 24.2k
Details
- First release
- Sep 15, 2020
| Version | Released | |
|---|---|---|
v1.7.14
patch
42 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.14
patch
Dependencies (67)
+ 59 more |
|
v1.8.7
patch
42 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22482
GO-2023-1520
GHSA-q9hr-j4rf-8fjc
Aug 20, 2024
JWT audience claim is not verified in github.com/argoproj/argo-cd JWT audience claim is not verified in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.7
patch
Dependencies (68)
+ 60 more |
|
v1.8.6
patch
43 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22482
GO-2023-1520
GHSA-q9hr-j4rf-8fjc
Aug 20, 2024
JWT audience claim is not verified in github.com/argoproj/argo-cd JWT audience claim is not verified in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.6
patch
Dependencies (68)
+ 60 more |
|
v1.7.13
patch
43 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.13
patch
Dependencies (67)
+ 59 more |
|
v1.8.5
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22482
GO-2023-1520
GHSA-q9hr-j4rf-8fjc
Aug 20, 2024
JWT audience claim is not verified in github.com/argoproj/argo-cd JWT audience claim is not verified in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.5
patch
Dependencies (68)
+ 60 more |
|
v1.7.12
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.12
patch
Dependencies (67)
+ 59 more |
|
v1.8.4
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22482
GO-2023-1520
GHSA-q9hr-j4rf-8fjc
Aug 20, 2024
JWT audience claim is not verified in github.com/argoproj/argo-cd JWT audience claim is not verified in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.4
patch
Dependencies (68)
+ 60 more |
|
v1.8.3
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22482
GO-2023-1520
GHSA-q9hr-j4rf-8fjc
Aug 20, 2024
JWT audience claim is not verified in github.com/argoproj/argo-cd JWT audience claim is not verified in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.3
patch
Dependencies (68)
+ 60 more |
|
v1.8.2
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22482
GO-2023-1520
GHSA-q9hr-j4rf-8fjc
Aug 20, 2024
JWT audience claim is not verified in github.com/argoproj/argo-cd JWT audience claim is not verified in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.2
patch
Dependencies (68)
+ 60 more |
|
v1.8.1
patch
43 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.1
patch
Dependencies (68)
+ 60 more |
|
v1.7.11
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.11
patch
Dependencies (67)
+ 59 more |
|
v1.8.0
minor
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.8.0
minor
Dependencies (68)
+ 60 more |
|
v1.8.0-rc2
pre
42 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.8.0-rc2
pre
Dependencies (68)
+ 60 more |
|
v1.8.0-rc1
pre
42 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.8.0-rc1
pre
Dependencies (68)
+ 60 more |
|
v1.7.10
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.10
patch
Dependencies (67)
+ 59 more |
|
v1.7.9
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.9
patch
Dependencies (67)
+ 59 more |
|
v1.7.8
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.8
patch
Dependencies (67)
+ 59 more |
|
v1.7.7
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.7
patch
Dependencies (67)
+ 59 more |
|
v1.7.6
patch
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.6
patch
Dependencies (67)
+ 59 more |
|
v1.7.5
initial
44 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-23216
GO-2025-3433
BIT-argo-cd-2025-23216
GHSA-47g2-qmh2-749v
Feb 04, 2025
Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-23347
GO-2022-0869
BIT-argo-cd-2021-23347
GHSA-qq5v-f4c3-395c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
Aug 21, 2024
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd Fixed in
1.7.13
1.8.6
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-1025
GO-2022-0516
CVE-2022-24768
GHSA-2f5v-8r3f-8pww
GHSA-96jv-vj39-x4j6
GO-2022-0359
Aug 21, 2024
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-31105
GO-2022-0518
GHSA-7943-82jg-wmw5
Aug 21, 2024
Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd Argo CD certificate verification is skipped for connections to OIDC providers in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31102
GO-2022-0517
GHSA-pmjg-52h9-72qv
Aug 21, 2024
Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd Argo CD SSO users vulnerable to Cross-site Scripting in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31016
GO-2022-0495
GHSA-jhqp-vf4w-rpwq
Aug 21, 2024
DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd DoS through large manifest files in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31035
GO-2022-0498
GHSA-h4w9-6x78-8vrj
Aug 21, 2024
Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd Argo CD's external URLs for Deployments can include JavaScript in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31034
GO-2022-0497
GHSA-2m7h-86qq-fp4v
Aug 21, 2024
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31036
GO-2022-0499
GHSA-q4w5-4gq2-98vm
Aug 21, 2024
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29165
GO-2022-0455
GHSA-r642-gv9p-2wjj
Aug 21, 2024
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24904
GO-2022-0453
GHSA-6gcg-hp2x-q54h
Aug 21, 2024
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24905
GO-2022-0454
GHSA-xmg8-99r8-jc2j
Aug 21, 2024
Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd Login screen allows message spoofing if SSO is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0387
GHSA-6w87-g839-9wv7
Aug 21, 2024
Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Helm OCI credentials leaked into Argo CD logs in github.com/argoproj/argo-cd Fixed in
1.7.14
1.8.7
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24731
GO-2022-0358
GHSA-h6h5-6fmq-rh28
Aug 21, 2024
Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24730
GO-2022-0357
GHSA-r9cr-hvjj-496v
Aug 21, 2024
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24348
GO-2022-0304
GHSA-63qx-x74g-jcr7
Aug 21, 2024
Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd Path traversal and dereference of symlinks in Argo CD in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40026
GO-2023-2085
GHSA-6jqw-jwf5-rp8h
Aug 21, 2024
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40584
GO-2023-2050
BIT-argo-cd-2023-40584
GHSA-g687-f2gx-6wm8
Aug 21, 2024
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40025
GO-2023-2018
GHSA-c8xw-vjgf-94hr
Aug 21, 2024
Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd Argo CD web terminal session doesn't expire in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40029
GO-2023-2049
BIT-argo-cd-2023-40029
GHSA-fwr2-64vr-xv9m
Aug 21, 2024
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41354
GO-2023-1670
GHSA-2q5c-qw9c-fmvq
Aug 20, 2024
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-23947
GO-2023-1577
GHSA-3jfq-742w-xg8j
Aug 20, 2024
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-22736
GO-2023-1512
GHSA-6p4m-hw2h-6gmw
Aug 20, 2024
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41666
GO-2024-3006
BIT-argo-cd-2024-41666
GHSA-v8wx-v5jq-qhhw
Aug 06, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-40634
GO-2024-3002
BIT-argo-cd-2024-40634
GHSA-jmvp-698c-4x3w
Aug 06, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-36106
GO-2024-2898
BIT-argo-cd-2024-36106
GHSA-3cqf-953p-h5cp
Jun 28, 2024
Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37152
GO-2024-2902
BIT-argo-cd-2024-37152
GHSA-87p9-x75h-p4j2
Jun 14, 2024
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31989
GO-2024-2877
BIT-argo-cd-2024-31989
GHSA-9766-5277-j5hr
Jun 05, 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache in github.com/argoproj/argo-cd References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32476
GO-2024-2792
BIT-argo-cd-2024-32476
GHSA-9m6p-x4h2-6frq
Jun 04, 2024
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-31990
GO-2024-2728
BIT-argo-cd-2024-31990
GHSA-2gvw-w6fj-7m3c
Jun 04, 2024
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-28175
GO-2024-2646
BIT-argo-cd-2024-28175
GHSA-jwv5-8mqv-g387
Mar 22, 2024
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Due to the improper URL protocols filtering of links specified in the link.argocd.argoproj.io annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. A malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-50726
GO-2024-2643
BIT-argo-cd-2023-50726
GHSA-g623-jcgg-mhmm
Mar 22, 2024
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source. References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-21661
GHSA-6v85-wr92-q4p7
BIT-argo-cd-2024-21661
GO-2024-2654
Mar 18, 2024
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAn attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. DetailsThe vulnerability is rooted in the application's code, where an array is being modified while it is being iterated over. This is a classic programming error but becomes critically unsafe when executed in a multi-threaded environment. When two threads interact with the same array simultaneously, the application crashes. The core issue is located in expireOldFailedAttempts function:
The function modifies the array while iterating it which means the code will cause an error and crash the application pod, inspecting the logs just before the crash we can confirm:
PoCTo reproduce the vulnerability, you can use the following steps:
ImpactThis is a Denial of Service (DoS) vulnerability. Any attacker can crash the application continuously, making it impossible for legitimate users to access the service. The issue is exacerbated because it does not require authentication, widening the pool of potential attackers. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22424
GHSA-92mw-q256-5vwg
Jan 19, 2024
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
ImpactThe Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.16 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain, such as https://argo-cd.internal.example.com. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). PatchesA patch for this vulnerability has been released in the following Argo CD versions:
🚨 The patch contains a breaking API change. 🚨 The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. WorkaroundsThe only way to completely resolve the issue is to upgrade. CreditsThe Argo CD team would like to express their gratitude to An Trinh of Calif who reported the issue confidentially according to our guidelines and published a helpful blog post to describe the issue. We would also like to thank them for actively participating in the review for the patch. References
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8828
GHSA-h8jc-jmrf-9h8f
BIT-argo-cd-2020-8828
Jul 26, 2021
Argo CD Insecure default administrative password
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. Workaround:The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. References
Updated Aug 07, 2024 · Source: OSV.dev |
v1.7.5
initial
Dependencies (67)
+ 59 more |