CVE-2025-55190High· 8.8▾ MidnightPoC availableAn information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 1.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
5.3%
Last analysed / modified upstream
Nuclei ×1 (last check)
9.9 → 8.8
critical → high
An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.
github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials — rated Important by Red Hat. Released 2025-09-04, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15387 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15388 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15389
Workarounds / mitigations:
Affected packages:
github.com/argoproj/argo-cd/v2 >= 2.13.0, < 2.13.9github.com/argoproj/argo-cd/v2 >= 2.14.0, < 2.14.16github.com/argoproj/argo-cd/v3 < 3.0.14github.com/argoproj/argo-cd/v3 >= 3.1.0-rc1, < 3.1.2Patched in:
github.com/argoproj/argo-cd/v2 2.13.9github.com/argoproj/argo-cd/v2 2.14.16github.com/argoproj/argo-cd/v3 3.0.14github.com/argoproj/argo-cd/v3 3.1.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50151Medium· 5.9oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)
CVE-2026-71577Medium· 6.3A flaw was found in multicluster-global-hub
CVE-2026-91203Medium· 6.0A flaw was found in cockpit-files
CVE-2026-92747Medium· 5.0A flaw was found in `cockpit-machines`
CVE-2026-93558High· 7.5A flaw was found in Netty's WebSocketServerExtensionHandler
CVE-2026-93578Medium· 5.9A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client