CVE-2025-55191Medium· 4.3▾ SunlitA race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
0.4% → 0.5%
Last analysed / modified upstream
6.5 → 4.3
A race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same repository URL. A valid API token with repositories resource permissions (create, update, or delete actions) is required to trigger the race condition.
github.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash — rated Moderate by Red Hat. Released 2025-09-30, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:17730 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:17731 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:18093
Workarounds / mitigations:
Affected packages:
github.com/argoproj/argo-cd/v2 >= 2.1.0, < 2.14.20github.com/argoproj/argo-cd/v3 >= 3.2.0-rc1, < 3.2.0-rc2github.com/argoproj/argo-cd/v3 >= 3.1.0-rc1, < 3.1.8github.com/argoproj/argo-cd/v3 >= 3.0.0-rc1, < 3.0.19Patched in:
github.com/argoproj/argo-cd/v2 2.14.20github.com/argoproj/argo-cd/v3 3.2.0-rc2github.com/argoproj/argo-cd/v3 3.1.8github.com/argoproj/argo-cd/v3 3.0.19Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-15801High· 8.0A vulnerability was found in CRI-O related to the container checkpoint and restore feature
CVE-2026-93433Medium· 5.5A flaw was found in libstoragemgmt
CVE-2026-92382Medium· 4.1An out-of-bounds write flaw was found in usbredir
CVE-2026-94449High· 7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror