github.com/argoproj/argo-workflows/v2
Workflow Engine for Kubernetes
Activity
- Latest release
- 5y ago
- Total releases
- 7
- Cadence
- ~13 days
- Last 12 months
- 0
Reach
- Stars
- 17.0k
Details
- First release
- Feb 01, 2021
| Version | Released | |
|---|---|---|
v2.12.13
patch
18 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-53862
GO-2024-3303
BIT-argo-workflows-2024-53862
GHSA-h36c-m3rf-34h9
Dec 02, 2024
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows Argo Workflows Allows Access to Archived Workflows with Fake Token in References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47827
GO-2024-3226
BIT-argo-workflows-2024-47827
GHSA-ghjw-32xw-ffwr
Oct 30, 2024
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37914
GO-2022-0928
BIT-argo-workflows-2021-37914
GHSA-h563-xh25-x54q
Aug 21, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0405
GHSA-prqf-xr2j-xf65
Aug 21, 2024
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0388
GHSA-6c73-2v8x-qpvm
Aug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Updated Mar 03, 2026 · Source: OSV.dev |
v2.12.13
patch
Dependencies (58)
+ 50 more |
|
v2.12.12
patch
18 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-53862
GO-2024-3303
BIT-argo-workflows-2024-53862
GHSA-h36c-m3rf-34h9
Dec 02, 2024
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows Argo Workflows Allows Access to Archived Workflows with Fake Token in References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47827
GO-2024-3226
BIT-argo-workflows-2024-47827
GHSA-ghjw-32xw-ffwr
Oct 30, 2024
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37914
GO-2022-0928
BIT-argo-workflows-2021-37914
GHSA-h563-xh25-x54q
Aug 21, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0405
GHSA-prqf-xr2j-xf65
Aug 21, 2024
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0388
GHSA-6c73-2v8x-qpvm
Aug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Updated Mar 03, 2026 · Source: OSV.dev |
v2.12.12
patch
Dependencies (58)
+ 50 more |
|
v2.12.11
patch
18 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-53862
GO-2024-3303
BIT-argo-workflows-2024-53862
GHSA-h36c-m3rf-34h9
Dec 02, 2024
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows Argo Workflows Allows Access to Archived Workflows with Fake Token in References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47827
GO-2024-3226
BIT-argo-workflows-2024-47827
GHSA-ghjw-32xw-ffwr
Oct 30, 2024
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37914
GO-2022-0928
BIT-argo-workflows-2021-37914
GHSA-h563-xh25-x54q
Aug 21, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0405
GHSA-prqf-xr2j-xf65
Aug 21, 2024
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0388
GHSA-6c73-2v8x-qpvm
Aug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Updated Mar 03, 2026 · Source: OSV.dev |
v2.12.11
patch
Dependencies (58)
+ 50 more |
|
v2.12.10
patch
18 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-53862
GO-2024-3303
BIT-argo-workflows-2024-53862
GHSA-h36c-m3rf-34h9
Dec 02, 2024
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows Argo Workflows Allows Access to Archived Workflows with Fake Token in References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47827
GO-2024-3226
BIT-argo-workflows-2024-47827
GHSA-ghjw-32xw-ffwr
Oct 30, 2024
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37914
GO-2022-0928
BIT-argo-workflows-2021-37914
GHSA-h563-xh25-x54q
Aug 21, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0405
GHSA-prqf-xr2j-xf65
Aug 21, 2024
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0388
GHSA-6c73-2v8x-qpvm
Aug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Updated Mar 03, 2026 · Source: OSV.dev |
v2.12.10
patch
Dependencies (58)
+ 50 more |
|
v2.12.9
patch
18 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-53862
GO-2024-3303
BIT-argo-workflows-2024-53862
GHSA-h36c-m3rf-34h9
Dec 02, 2024
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows Argo Workflows Allows Access to Archived Workflows with Fake Token in References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47827
GO-2024-3226
BIT-argo-workflows-2024-47827
GHSA-ghjw-32xw-ffwr
Oct 30, 2024
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37914
GO-2022-0928
BIT-argo-workflows-2021-37914
GHSA-h563-xh25-x54q
Aug 21, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0405
GHSA-prqf-xr2j-xf65
Aug 21, 2024
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0388
GHSA-6c73-2v8x-qpvm
Aug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Updated Mar 03, 2026 · Source: OSV.dev |
v2.12.9
patch
Dependencies (58)
+ 50 more |
|
v2.12.8
patch
18 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-53862
GO-2024-3303
BIT-argo-workflows-2024-53862
GHSA-h36c-m3rf-34h9
Dec 02, 2024
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows Argo Workflows Allows Access to Archived Workflows with Fake Token in References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47827
GO-2024-3226
BIT-argo-workflows-2024-47827
GHSA-ghjw-32xw-ffwr
Oct 30, 2024
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37914
GO-2022-0928
BIT-argo-workflows-2021-37914
GHSA-h563-xh25-x54q
Aug 21, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0405
GHSA-prqf-xr2j-xf65
Aug 21, 2024
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0388
GHSA-6c73-2v8x-qpvm
Aug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Updated Mar 03, 2026 · Source: OSV.dev |
v2.12.8
patch
Dependencies (58)
+ 50 more |
|
v2.12.7
initial
18 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-53862
GO-2024-3303
BIT-argo-workflows-2024-53862
GHSA-h36c-m3rf-34h9
Dec 02, 2024
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows Argo Workflows Allows Access to Archived Workflows with Fake Token in References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47827
GO-2024-3226
BIT-argo-workflows-2024-47827
GHSA-ghjw-32xw-ffwr
Oct 30, 2024
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37914
GO-2022-0928
BIT-argo-workflows-2021-37914
GHSA-h563-xh25-x54q
Aug 21, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0405
GHSA-prqf-xr2j-xf65
Aug 21, 2024
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0388
GHSA-6c73-2v8x-qpvm
Aug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Updated Mar 03, 2026 · Source: OSV.dev |
v2.12.7
initial
Dependencies (58)
+ 50 more |