{"id":"CVE-2025-55191","title":"github.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash (CVE-2025-55191)","summary":"A race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cvssSource":"vendor","cwe":"CWE-362","vendor":"Red Hat","product":"Red Hat OpenShift GitOps 1.16","affected":["developer_hub","openshift_gitops","openshift_gitops 1.16","openshift_gitops 1.17","openshift_gitops 1.18"],"patched":["openshift_gitops 1.16","openshift_gitops 1.17","openshift_gitops 1.18"],"published":"2025-09-30","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:10:46+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55191.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55191.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-55191"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2400562"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-55191"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55191"},{"url":"https://github.com/argoproj/argo-cd/commit/701bc50d01c752cad96185f848088d287a97c7b7"},{"url":"https://github.com/argoproj/argo-cd/pull/6103"},{"url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-g88p-r42r-ppp9"},{"url":"https://access.redhat.com/errata/RHSA-2025:17730"},{"url":"https://access.redhat.com/errata/RHSA-2025:17731"},{"url":"https://access.redhat.com/errata/RHSA-2025:18093"},{"url":"https://github.com/argoproj/argo-cd"},{"url":"https://pkg.go.dev/vuln/GO-2025-3994"}],"tags":["csaf","vex","red-hat","osv","go","score-dispute"],"epss":0.00472,"epssPercentile":0.39891,"aliases":["GHSA-g88p-r42r-ppp9","BIT-argo-cd-2025-55191","GO-2025-3994"],"ecosystem":"go","scores":{"vendor":4.3,"osv":6.5},"ingestedAt":"2026-08-24T19:25:44.633Z","slug":"CVE-2025-55191","body":"## Overview\n\nA race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same repository URL. A valid API token with repositories resource permissions (create, update, or delete actions) is required to trigger the race condition.\n\n## Vendor advisories\n\n- **RHSA-2025:17730** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.16 · released 2025-10-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:17730)\n- **RHSA-2025:17731** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.17 · released 2025-10-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:17731)\n- **RHSA-2025:18093** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.18 · released 2025-10-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:18093)\n- **Red Hat VEX** · Moderate · affected: Red Hat Developer Hub, Red Hat OpenShift GitOps · no fix planned: Red Hat Developer Hub, Red Hat OpenShift GitOps · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55191.json)\n\n**github.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash** — rated Moderate by Red Hat. Released 2025-09-30, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Developer Hub\n- Red Hat OpenShift GitOps\n\nFixed:\n\n- Red Hat OpenShift GitOps 1.16\n- Red Hat OpenShift GitOps 1.17\n- Red Hat OpenShift GitOps 1.18\n\nNo fix planned:\n\n- Red Hat Developer Hub\n- Red Hat OpenShift GitOps\n\nNot affected:\n\n- Red Hat OpenShift GitOps 1.16\n- Red Hat OpenShift GitOps 1.17\n- Red Hat OpenShift GitOps 1.18\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:17730\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:17731\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:18093\n\nWorkarounds / mitigations:\n\n- Systems may be configured to automatically restart a service upon crash and doing so may partially mitigate the availability impact of this vulnerability.\n\n## Package advisory (CVE-2025-55191)\n\nAffected packages:\n\n- `github.com/argoproj/argo-cd/v2 >= 2.1.0, < 2.14.20`\n- `github.com/argoproj/argo-cd/v3 >= 3.2.0-rc1, < 3.2.0-rc2`\n- `github.com/argoproj/argo-cd/v3 >= 3.1.0-rc1, < 3.1.8`\n- `github.com/argoproj/argo-cd/v3 >= 3.0.0-rc1, < 3.0.19`\n\nPatched in:\n\n- `github.com/argoproj/argo-cd/v2 2.14.20`\n- `github.com/argoproj/argo-cd/v3 3.2.0-rc2`\n- `github.com/argoproj/argo-cd/v3 3.1.8`\n- `github.com/argoproj/argo-cd/v3 3.0.19`\n\nSource: https://osv.dev/vulnerability/GHSA-g88p-r42r-ppp9","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208969,"id":"CVE-2025-55191","ts":1790062303651,"field":"cvss","old":"6.5","new":"4.3"}]}