github.com/argoproj/argo-workflows/v3 vulnerabilities
CVEs whose affected-version data names the github.com/argoproj/argo-workflows/v3 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-54526HighArgo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.36%via GHSA
CVE-2026-42294High· 7.5Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
▾ Twilightargoproj · github.com/argoproj/argo-workflows/v3EPSS 0.61%via OSV
CVE-2026-40886High· 7.7Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.38%via OSV
CVE-2026-28229High· 7.5Unauthorized access to Argo Workflows Template
Unauthorized access to Argo Workflows Template
▾ Twilightargoproj · github.com/argoproj/argo-workflows/v3EPSS 0.65%via OSV
CVE-2026-31892HighArgo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.49%via OSV