github.com/argoproj/argo-workflows vulnerabilities
CVEs whose affected-version data names the github.com/argoproj/argo-workflows package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54526HighArgo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.36%via GHSA
CVE-2026-31892HighArgo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.49%via OSV