CVE-2025-62157Medium· 6.5▾ SunlitArgo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in a namespace running Argo Workflows can read the workflow-controller logs and obtain credentials to the artifact repository. Update to versions 3.6.12 or 3.7.3 to remediate the vulnerability. No known workarounds exist.
argo_workflows < 3.6.12argo_workflows >= 3.7.0, < 3.7.3Upgrade past the affected range:
argo_workflows 3.7.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62156High· 8.1Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes
CVE-2026-42295HighArgo vulnerable to exposure of artifact repository credentials
CVE-2026-23960Medium· 5.4Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes
CVE-2022-27544Medium· 5.0BigFix Web Reports authorized users may see SMTP credentials in clear text.
CVE-2020-5404Medium· 5.9The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain
CVE-2019-11284High· 8.6Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones