github.com/argoproj/argo-cd/v2
Declarative Continuous Deployment for Kubernetes
Activity
- Latest release
- 10mo ago
- Total releases
- 20
- Cadence
- ~7 days
- Last 12 months
- 1
Reach
- Stars
- 24.2k
Details
- First release
- Feb 05, 2025
| Version | Released | |
|---|---|---|
v2.14.21
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev |
v2.14.21
patch
Dependencies (111)
+ 103 more |
|
v2.14.20
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev |
v2.14.20
patch
Dependencies (111)
+ 103 more |
|
v2.14.19
patch
7 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev |
v2.14.19
patch
Dependencies (111)
+ 103 more |
|
v2.14.18
patch
7 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev |
v2.14.18
patch
Dependencies (111)
+ 103 more |
|
v2.14.17
patch
7 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev |
v2.14.17
patch
Dependencies (111)
+ 103 more |
|
v2.14.16
patch
7 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev |
v2.14.16
patch
Dependencies (111)
+ 103 more |
|
v2.14.15
patch
8 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.15
patch
Dependencies (111)
+ 103 more |
|
v2.14.14
patch
8 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.14
patch
Dependencies (111)
+ 103 more |
|
v2.14.13
patch
8 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.13
patch
Dependencies (111)
+ 103 more |
|
v2.14.12
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.12
patch
Dependencies (111)
+ 103 more |
|
v2.14.11
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.11
patch
Dependencies (111)
+ 103 more |
|
v2.14.10
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.10
patch
Dependencies (111)
+ 103 more |
|
v2.14.9
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.9
patch
Dependencies (111)
+ 103 more |
|
v2.14.8
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.8
patch
Dependencies (111)
+ 103 more |
|
v2.14.7
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.7
patch
Dependencies (111)
+ 103 more |
|
v2.14.6
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.6
patch
Dependencies (111)
+ 103 more |
|
v2.14.5
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.5
patch
Dependencies (111)
+ 103 more |
|
v2.14.4
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.4
patch
Dependencies (111)
+ 103 more |
|
v2.14.3
patch
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.3
patch
Dependencies (111)
+ 103 more |
|
v2.14.2
initial
9 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
2.14.20
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
2.13.9
2.14.16
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
2.13.8
2.14.13
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.14.2
initial
Dependencies (111)
+ 103 more |