CVE-2024-32476Medium· 6.5▾ SunlitArgo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
DoS vuln via OOM using jq in ignoreDifferences.
ignoreDifferences:
- group: apps
kind: Deployment
jqPathExpressions:
- 'until(true == false; [.] + [1])'
A patch for this vulnerability has been released in the following Argo CD versions:
v2.10.8 v2.9.13 v2.8.17
If you have any questions or comments about this advisory:
Open an issue in the Argo CD issue tracker or discussions Join us on Slack in channel #argo-cd
Credits This vulnerability was found & reported by @crenshaw-dev (Michael Crenshaw)
The Argo team would like to thank these contributors for their responsible disclosure and constructive communications during the resolve of this issue
github.com/argoproj/argo-cd/v2 >= 2.10.0, < 2.10.8github.com/argoproj/argo-cd/v2 >= 2.9.0, < 2.9.13github.com/argoproj/argo-cd/v2 < 2.8.17Upgrade to a patched release:
github.com/argoproj/argo-cd/v2 2.10.8github.com/argoproj/argo-cd/v2 2.9.13github.com/argoproj/argo-cd/v2 2.8.17Connected by shared product, vendor, weakness, or advisory.
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
CVE-2024-41666Medium· 4.7The Argo CD web terminal session does not handle the revocation of user permissions properly
CVE-2024-29893Medium· 6.5ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
CVE-2024-21652Medium· 5.4Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
CVE-2024-31990Medium· 4.8Argo CD's API server does not enforce project sourceNamespaces