VulnSea

github.com/argoproj/argo-cd/v2 vulnerabilities

CVEs whose affected-version data names the github.com/argoproj/argo-cd/v2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

16 CVEsRSS

CVE-2025-47933Critical· 9.0
1y ago

Argo CD allows cross-site scripting on repositories page

Argo CD allows cross-site scripting on repositories page

Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.46%via OSV
CVE-2025-23216Medium· 6.8
1y ago

Argo CD does not scrub secret values from patch errors

Argo CD does not scrub secret values from patch errors

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.47%via OSV
CVE-2024-41666Medium· 4.7
2y ago

The Argo CD web terminal session does not handle the revocation of user permissions properly

The Argo CD web terminal session does not handle the revocation of user permissions properly

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.69%via OSV
CVE-2024-32476Medium· 6.5
2y ago

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 1.0%via OSV
CVE-2024-31990Medium· 4.8
2y ago

Argo CD's API server does not enforce project sourceNamespaces

Argo CD's API server does not enforce project sourceNamespaces

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.45%via OSV
CVE-2024-29893Medium· 6.5
2y ago

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.97%via OSV
CVE-2024-21661High· 7.5
2y ago

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Twilightargoproj · github.com/argoproj/argo-cdEPSS 1.2%via OSV
CVE-2024-21652Medium· 5.4
2y ago

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.75%via OSV
CVE-2024-28175Critical· 9.0
2y ago

Cross-site scripting on application summary component

Cross-site scripting on application summary component

Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.65%via OSV
CVE-2023-50726Medium· 6.4
2y ago

Users with `create` but not `override` privileges can perform local sync

Users with `create` but not `override` privileges can perform local sync

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.53%via OSV
CVE-2024-22424High· 8.3
2y ago

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

Twilightargoproj · github.com/argoproj/argo-cdEPSS 0.39%via OSV
CVE-2023-40026Medium· 5.0
2y ago

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.50%via OSV
CVE-2022-41354Medium· 5.3
3y ago

Argo CD authenticated but unauthorized users may enumerate Application names via the API

Argo CD authenticated but unauthorized users may enumerate Application names via the API

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.64%via OSV
CVE-2023-22736High· 8.5
3y ago

Controller reconciles apps outside configured namespaces when sharding is enabled

Controller reconciles apps outside configured namespaces when sharding is enabled

Twilightargoproj · github.com/argoproj/argo-cd/v2EPSS 0.78%via OSV
CVE-2022-24348High· 7.7PoC
4y ago

Path traversal and dereference of symlinks in Argo CD

Path traversal and dereference of symlinks in Argo CD

Midnightargoproj · github.com/argoproj/argo-cd/v2EPSS 2.7%via OSV
CVE-2021-23347Medium· 4.7
5y ago

Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2

Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.53%via OSV
github.com/argoproj/argo-cd/v2 vulnerabilities (CVEs) · VulnSea