github.com/argoproj/argo-workflows/v3
Workflow Engine for Kubernetes
Activity
- Latest release
- 1mo ago
- Total releases
- 60
- Cadence
- ~22 days
- Last 12 months
- 17
Reach
- Stars
- 17.0k
Details
- First release
- Feb 23, 2021
| Version | Released | |
|---|---|---|
v3.7.18
patch
4 CVEs
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev |
v3.7.18
patch
Dependencies (94)
+ 86 more |
|
v3.7.17
patch
4 CVEs
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev |
v3.7.17
patch
Dependencies (94)
+ 86 more |
|
v3.7.16
patch
4 CVEs
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev |
v3.7.16
patch
Dependencies (94)
+ 86 more |
|
v3.7.15
patch
4 CVEs
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev |
v3.7.15
patch
Dependencies (94)
+ 86 more |
|
v3.7.14
patch
5 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev |
v3.7.14
patch
Dependencies (94)
+ 86 more |
|
v3.7.13
patch
7 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev |
v3.7.13
patch
Dependencies (94)
+ 86 more |
|
v3.7.12
patch
7 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev |
v3.7.12
patch
Dependencies (94)
+ 86 more |
|
v3.7.11
patch
7 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev |
v3.7.11
patch
Dependencies (94)
+ 86 more |
|
v3.7.10
patch
9 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v3.7.10
patch
Dependencies (94)
+ 86 more |
|
v3.7.9
patch
9 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v3.7.9
patch
Dependencies (94)
+ 86 more |
|
v3.7.8
patch
9 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v3.7.8
patch
Dependencies (94)
+ 86 more |
|
v3.7.7
patch
10 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.7
patch
Dependencies (94)
+ 86 more |
|
v3.7.6
patch
10 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.6
patch
Dependencies (94)
+ 86 more |
|
v3.7.5
patch
10 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.5
patch
Dependencies (94)
+ 86 more |
|
v3.6.13
patch
11 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.6.13
patch
Dependencies (83)
+ 75 more |
|
v3.7.4
patch
11 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.4
patch
Dependencies (93)
+ 85 more |
|
v3.7.3
patch
11 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.3
patch
Dependencies (93)
+ 85 more |
|
v3.7.2
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.2
patch
Dependencies (93)
+ 85 more |
|
v3.7.1
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.1
patch
Dependencies (93)
+ 85 more |
|
v3.7.0
minor
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.0
minor
Dependencies (94)
+ 86 more |
|
v3.7.0-rc4
pre
9 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v3.7.0-rc4
pre
Dependencies (94)
+ 86 more |
|
v3.7.0-rc3
pre
9 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v3.7.0-rc3
pre
Dependencies (94)
+ 86 more |
|
v3.6.10
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.6.10
patch
Dependencies (83)
+ 75 more |
|
v3.7.0-rc1
pre
9 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v3.7.0-rc1
pre
Dependencies (93)
+ 85 more |
|
v3.6.9
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.6.9
patch
Dependencies (83)
+ 75 more |
|
v3.6.8
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40886
GO-2026-5148
BIT-argo-workflows-2026-40886
GHSA-5jv8-h7qh-rf5p
Jun 25, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows Fixed in
3.7.14
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.6.8
patch
Dependencies (83)
+ 75 more |
|
v3.6.3
patch
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.6.3
patch
Dependencies (83)
+ 75 more |
|
v3.6.1
minor
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-53862
GHSA-h36c-m3rf-34h9
BIT-argo-workflows-2024-53862
GO-2024-3303
Dec 02, 2024
Access to Archived Argo Workflows with Fake Token in `client` mode
Medium
Network
Low
None
None
SummaryWhen using When using DetailsNo authentication is performed by the Server itself on In #12736 / v3.5.7 and #13021 / v3.5.8, the auth check was accidentally removed on the GET Workflow endpoint's fallback to archived workflows on these lines, allowing archived workflows to be retrieved with a fake token. PoCConfigurationController
Server: ReproductionVisit a completed, archived workflow URL with an invalid authorization token, this results in the workflow being displayed. For example, directly query the API and retrieve the workflow data (where
ImpactUsers of the Server with Users of the Server with [^1]: Fixed in
3.5.13
3.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.6.1
minor
Dependencies (83)
+ 75 more |
|
v3.6.0-rc2
pre
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.6.0-rc2
pre
Dependencies (82)
+ 74 more |
|
v3.4.17
patch
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.17
patch
Dependencies (72)
+ 64 more |
|
v3.5.6
minor
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.5.6
minor
Dependencies (75)
+ 67 more |
|
v3.4.14
patch
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.14
patch
Dependencies (72)
+ 64 more |
|
v3.4.12
patch
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.12
patch
Dependencies (72)
+ 64 more |
|
v3.4.5
patch
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.5
patch
Dependencies (68)
+ 60 more |
|
v3.4.1
minor
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.1
minor
Dependencies (67)
+ 59 more |
|
v3.4.0-rc4
pre
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.0-rc4
pre
Dependencies (67)
+ 59 more |
|
v3.3.5
patch
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.3.5
patch
Dependencies (62)
+ 54 more |
|
v3.3.4
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.3.4
patch
Dependencies (62)
+ 54 more |
|
v3.3.1
minor
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.3.1
minor
Dependencies (62)
+ 54 more |
|
v3.3.0-rc6
pre
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.3.0-rc6
pre
Dependencies (63)
+ 55 more |
|
v3.3.0-rc5
pre
12 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v3.3.0-rc5
pre
Dependencies (63)
+ 55 more |
|
v3.1.15
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.1.15
patch
Dependencies (64)
+ 56 more |
|
v3.1.14
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.1.14
patch
Dependencies (64)
+ 56 more |
|
v3.1.12
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.1.12
patch
Dependencies (64)
+ 56 more |
|
v3.1.11
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.1.11
patch
Dependencies (64)
+ 56 more |
|
v3.1.10
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.1.10
patch
Dependencies (64)
+ 56 more |
|
v3.1.9
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.1.9
patch
Dependencies (64)
+ 56 more |
|
v3.2.0-rc2
pre
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.2.0-rc2
pre
Dependencies (66)
+ 58 more |
|
v3.0.10
patch
13 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.0.10
patch
Dependencies (63)
+ 55 more |
|
v3.1.3
minor
16 CVEs
CVE-2026-54526
GO-2026-6223
BIT-argo-workflows-2026-54526
GHSA-48p8-g2fx-3wwm
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows Fixed in
3.7.15
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42297
GO-2026-5751
BIT-argo-workflows-2026-42297
GHSA-xchc-cqwg-g76q
Jun 25, 2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42183
GO-2026-5527
BIT-argo-workflows-2026-42183
GHSA-p4gq-3vxj-f4jq
Jun 25, 2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42294
GO-2026-5462
BIT-argo-workflows-2026-42294
GHSA-jcc8-g2q4-9fxq
Jun 25, 2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42295
GO-2026-5235
BIT-argo-workflows-2026-42295
GHSA-7vf8-2cr6-54mf
Jun 25, 2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-42296
GO-2026-5072
BIT-argo-workflows-2026-42296
GHSA-3775-99mw-8rp4
Jun 25, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows Fixed in
3.7.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-31892
GO-2026-4681
BIT-argo-workflows-2026-31892
GHSA-3wf5-g532-rcrr
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows Fixed in
3.7.11
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28229
GO-2026-4678
BIT-argo-workflows-2026-28229
GHSA-56px-hm34-xqj5
Mar 12, 2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows Fixed in
3.7.11
References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-23960
GO-2026-4350
BIT-argo-workflows-2026-23960
GHSA-cv78-6m8q-ph82
Feb 02, 2026
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows Fixed in
3.6.17
3.7.8
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66626
GO-2025-4223
BIT-argo-workflows-2025-66626
GHSA-xrqc-7xgx-c9vh
Dec 15, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows Fixed in
3.6.14
3.7.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62157
GO-2025-4024
BIT-argo-workflows-2025-62157
GHSA-c2hv-4pfj-mm2r
Nov 05, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-62156
GO-2025-4023
BIT-argo-workflows-2025-62156
GHSA-p84v-gxvw-73pf
Nov 05, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows Fixed in
3.6.12
3.7.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-37914
GO-2022-0928
BIT-argo-workflows-2021-37914
GHSA-h563-xh25-x54q
Aug 21, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows Fixed in
3.1.6
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0388
GHSA-6c73-2v8x-qpvm
Aug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows Fixed in
3.0.9
3.1.6
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0405
GHSA-prqf-xr2j-xf65
Aug 21, 2024
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with Fixed in
3.0.9
3.1.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29164
GHSA-cmv8-6362-r5w9
BIT-argo-workflows-2022-29164
May 23, 2022
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit. We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned. Fixed in
3.2.11
3.3.5
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.1.3
minor
Dependencies (64)
+ 56 more |