argoproj has 33 CVEs on record between 2021 and 2026. Cadence is steady at roughly 4 per quarter. The busiest recent month was May 2026 with 3. The median CVSS is 7.0 (high), with 5 rated critical. None have a confirmed exploitation report. Most affected products: github.com/argoproj/argo-cd (10), github.com/argoproj/argo-cd/v2 (9), github.com/argoproj/argo-workflows/v4 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- —
- Last 90 days
- 4 prev 4
Products
- github.com/argoproj/argo-cd 10
- github.com/argoproj/argo-cd/v2 9
- github.com/argoproj/argo-workflows/v4 4
- argo_cd 2
- github.com/argoproj/argo-workflows/v3 2
- argo-workflows 1
Worst active — by depth score
CVE-2026-42880Critical· 9.6ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction65CVE-2022-1025Critical· 9.9Improper access control allows admin privilege escalation in Argo CD55CVE-2022-24348High· 7.7Path traversal and dereference of symlinks in Argo CD55CVE-2025-47933Critical· 9.0Argo CD allows cross-site scripting on repositories page50CVE-2024-28175Critical· 9.0Cross-site scripting on application summary component50
argoproj vulnerabilities
CVEs affecting argoproj, newest first. Open any entry for full detail, references, and exploit status.
33 CVEsRSS
CVE-2026-93991High· 7.7Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. A…
CVE-2026-54526HighArgo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
CVE-2026-45738High· 7.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rende…
CVE-2026-45737Medium· 6.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configura…
CVE-2026-42880Critical· 9.6PoCArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-42294High· 7.5Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
CVE-2026-42295HighArgo vulnerable to exposure of artifact repository credentials
Argo vulnerable to exposure of artifact repository credentials
CVE-2026-40886High· 7.7Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
CVE-2026-28229High· 7.5Unauthorized access to Argo Workflows Template
Unauthorized access to Argo Workflows Template
CVE-2026-31892HighArgo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
CVE-2026-23960Medium· 5.4Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbit…
CVE-2025-47933Critical· 9.0Argo CD allows cross-site scripting on repositories page
Argo CD allows cross-site scripting on repositories page
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
Argo CD does not scrub secret values from patch errors
GHSA-274v-mgcv-cm8jMedium· 6.8Argo CD GitOps Engine does not scrub secret values from patch errors
Argo CD GitOps Engine does not scrub secret values from patch errors
CVE-2024-41666Medium· 4.7The Argo CD web terminal session does not handle the revocation of user permissions properly
The Argo CD web terminal session does not handle the revocation of user permissions properly
CVE-2024-37152Medium· 5.3PoCUnauthenticated Access to sensitive settings in Argo CD
Unauthenticated Access to sensitive settings in Argo CD
CVE-2024-36106Medium· 4.3Argo-cd authenticated users can enumerate clusters by name
Argo-cd authenticated users can enumerate clusters by name
CVE-2024-32476Medium· 6.5Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
CVE-2024-31990Medium· 4.8Argo CD's API server does not enforce project sourceNamespaces
Argo CD's API server does not enforce project sourceNamespaces
CVE-2024-29893Medium· 6.5ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
CVE-2024-21661High· 7.5Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
CVE-2024-21652Medium· 5.4Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
CVE-2024-28175Critical· 9.0Cross-site scripting on application summary component
Cross-site scripting on application summary component
CVE-2023-50726Medium· 6.4Users with `create` but not `override` privileges can perform local sync
Users with `create` but not `override` privileges can perform local sync
CVE-2024-22424High· 8.3github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
CVE-2023-40026Medium· 5.0Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
CVE-2022-41354Medium· 5.3Argo CD authenticated but unauthorized users may enumerate Application names via the API
Argo CD authenticated but unauthorized users may enumerate Application names via the API
CVE-2023-23947Critical· 9.1Users with any cluster secret update access may update out-of-bounds cluster secrets
Users with any cluster secret update access may update out-of-bounds cluster secrets
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2022-25856High· 7.5Insecure path traversal in Git Trigger Source can lead to arbitrary file read
Insecure path traversal in Git Trigger Source can lead to arbitrary file read