github.com/argoproj/argo-cd/v3
Declarative Continuous Deployment for Kubernetes
Activity
- Latest release
- 2d ago
- Total releases
- 51
- Cadence
- ~7 days
- Last 12 months
- 34
Reach
- Stars
- 23.8k
Details
- First release
- Mar 17, 2025
| Version | Released | |
|---|---|---|
v3.3.13
patch
|
v3.3.13
patch
Dependencies (113)
+ 105 more |
|
v3.5.0-rc3
pre
|
v3.5.0-rc3
pre
Dependencies (125)
+ 117 more |
|
v3.4.5
patch
|
v3.4.5
patch
Dependencies (121)
+ 113 more |
|
v3.5.0-rc1
pre
|
v3.5.0-rc1
pre
Dependencies (125)
+ 117 more |
|
v3.4.3
patch
|
v3.4.3
patch
Dependencies (121)
+ 113 more |
|
v3.2.12
patch
|
v3.2.12
patch
Dependencies (112)
+ 104 more |
|
v3.4.1
patch
2 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.4.1
patch
Dependencies (121)
+ 113 more |
|
v3.4.0
minor
2 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.4.0
minor
Dependencies (121)
+ 113 more |
|
v3.4.0-rc7
pre
2 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.4.0-rc7
pre
Dependencies (121)
+ 113 more |
|
v3.2.10
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.2.10
patch
Dependencies (112)
+ 104 more |
|
v3.1.15
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.1.15
patch
Dependencies (113)
+ 105 more |
|
v3.2.9
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.2.9
patch
Dependencies (112)
+ 104 more |
|
v3.1.14
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.1.14
patch
Dependencies (113)
+ 105 more |
|
v3.3.7
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.3.7
patch
Dependencies (113)
+ 105 more |
|
v3.4.0-rc4
pre
2 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.4.0-rc4
pre
Dependencies (121)
+ 113 more |
|
v3.3.5
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.3.5
patch
Dependencies (113)
+ 105 more |
|
v3.3.4
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.3.4
patch
Dependencies (113)
+ 105 more |
|
v3.4.0-rc1
pre
2 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.4.0-rc1
pre
Dependencies (121)
+ 113 more |
|
v3.3.2
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.3.2
patch
Dependencies (113)
+ 105 more |
|
v3.3.1
minor
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.3.1
minor
Dependencies (113)
+ 105 more |
|
v3.1.12
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.1.12
patch
Dependencies (113)
+ 105 more |
|
v3.0.23
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.0.23
patch
Dependencies (112)
+ 104 more |
|
v3.0.22
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.0.22
patch
Dependencies (112)
+ 104 more |
|
v3.1.11
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.1.11
patch
Dependencies (113)
+ 105 more |
|
v3.2.4
patch
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.2.4
patch
Dependencies (112)
+ 104 more |
|
v3.0.21
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.0.21
patch
Dependencies (112)
+ 104 more |
|
v3.1.10
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.1.10
patch
Dependencies (113)
+ 105 more |
|
v3.3.0-rc3
pre
2 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.3.0-rc3
pre
Dependencies (113)
+ 105 more |
|
v3.2.1
minor
3 CVEs
CVE-2026-45737
GO-2026-5618
BIT-argo-cd-2026-45737
GHSA-rg3g-4rw9-gqrp
Jun 25, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-42880
GO-2026-5099
BIT-argo-cd-2026-42880
CVE-2026-43824
GHSA-3v3m-wc6v-x4x3
Jun 25, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd Fixed in
3.2.11
3.3.9
References Updated Jul 08, 2026 · Source: OSV.dev |
v3.2.1
minor
Dependencies (112)
+ 104 more |
|
v3.1.9
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.1.9
patch
Dependencies (113)
+ 105 more |
|
v3.2.0-rc2
pre
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.2.0-rc2
pre
Dependencies (113)
+ 105 more |
|
v3.1.8
patch
1 CVE
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev |
v3.1.8
patch
Dependencies (113)
+ 105 more |
|
v3.1.6
patch
5 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev |
v3.1.6
patch
Dependencies (113)
+ 105 more |
|
v3.1.3
minor
5 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev |
v3.1.3
minor
Dependencies (113)
+ 105 more |
|
v3.0.13
patch
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.13
patch
Dependencies (112)
+ 104 more |
|
v3.1.0-rc4
pre
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.1.0-rc4
pre
Dependencies (113)
+ 105 more |
|
v3.0.11
patch
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.11
patch
Dependencies (112)
+ 104 more |
|
v3.0.10
patch
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.10
patch
Dependencies (112)
+ 104 more |
|
v3.1.0-rc2
pre
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.1.0-rc2
pre
Dependencies (113)
+ 105 more |
|
v3.1.0-rc1
pre
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.1.0-rc1
pre
Dependencies (113)
+ 105 more |
|
v3.0.8
patch
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.8
patch
Dependencies (112)
+ 104 more |
|
v3.0.7
patch
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.7
patch
Dependencies (112)
+ 104 more |
|
v3.0.6
patch
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.6
patch
Dependencies (112)
+ 104 more |
|
v3.0.5
patch
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.5
patch
Dependencies (112)
+ 104 more |
|
v3.0.4
patch
6 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.4
patch
Dependencies (112)
+ 104 more |
|
v3.0.2
patch
7 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.2
patch
Dependencies (112)
+ 104 more |
|
v3.0.0-rc6
pre
7 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.0-rc6
pre
Dependencies (112)
+ 104 more |
|
v3.0.0-rc5
pre
7 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.0-rc5
pre
Dependencies (112)
+ 104 more |
|
v3.0.0-rc3
pre
7 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.0-rc3
pre
Dependencies (112)
+ 104 more |
|
v3.0.0-rc2
pre
7 CVEs
CVE-2026-45738
GO-2026-5418
BIT-argo-cd-2026-45738
GHSA-h98r-wv3h-fr38
Jun 25, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd Fixed in
3.2.12
3.3.10
3.4.2
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-55191
GO-2025-3994
BIT-argo-cd-2025-55191
GHSA-g88p-r42r-ppp9
Oct 23, 2025
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59531
GO-2025-3993
BIT-argo-cd-2025-59531
GHSA-f9gq-prrc-hrhc
Oct 23, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-59538
GO-2025-3995
BIT-argo-cd-2025-59538
GHSA-gpx4-37g2-c8pv
Oct 23, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Oct 23, 2025 · Source: OSV.dev
CVE-2025-59537
GO-2025-3996
BIT-argo-cd-2025-59537
GHSA-wp4p-9pxh-cgx2
Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd Fixed in
3.0.19
3.1.8
3.2.0-rc2
References Updated Apr 20, 2026 · Source: OSV.dev
CVE-2025-55190
GO-2025-3934
BIT-argo-cd-2025-55190
GHSA-786q-9hcg-v9ff
Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd Fixed in
3.0.14
3.1.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-47933
GO-2025-3720
BIT-argo-cd-2025-47933
GHSA-2hj5-g64g-fp6p
May 29, 2025
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.0-rc2
pre
Dependencies (112)
+ 104 more |