---
id: CVE-2025-61560
title: >-
  A race condition vulnerability in the SessionManager of CNCF: Cloud Native
  Computing Foundation Argo CD v3.0.6 allows attackers to bypass rate limiting
  and perform a brute force attack via repeated crafted requests.
summary: >-
  A race condition vulnerability in the SessionManager of CNCF: Cloud Native
  Computing Foundation Argo CD v3.0.6 allows attackers to bypass rate limiting
  and perform a brute force attack via repeated crafted requests.
severity: none
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:41:15.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61560'
references:
  - url: 'https://github.com/argoproj/argo-cd/'
    label: cve@mitre.org
  - url: >-
      https://github.com/argoproj/argo-cd/security/advisories/GHSA-4439-h7jw-5cjj
    label: cve@mitre.org
tags:
  - nvd
ingestedAt: '2026-10-09T18:07:39.415Z'
---

## Overview

A race condition vulnerability in the SessionManager of CNCF: Cloud Native Computing Foundation Argo CD v3.0.6 allows attackers to bypass rate limiting and perform a brute force attack via repeated crafted requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
