VulnSea

argoproj has 33 CVEs on record between 2021 and 2026. Cadence is steady at roughly 4 per quarter. The busiest recent month was May 2026 with 3. The median CVSS is 7.0 (high), with 5 rated critical. None have a confirmed exploitation report. Most affected products: github.com/argoproj/argo-cd (10), github.com/argoproj/argo-cd/v2 (9), github.com/argoproj/argo-workflows/v4 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
Last 90 days
4 prev 4

Products

  • github.com/argoproj/argo-cd 10
  • github.com/argoproj/argo-cd/v2 9
  • github.com/argoproj/argo-workflows/v4 4
  • argo_cd 2
  • github.com/argoproj/argo-workflows/v3 2
  • argo-workflows 1
33
Total CVEs
5
Critical
0
CISA KEV
0
Exploited

argoproj vulnerabilities

CVEs affecting argoproj, newest first. Open any entry for full detail, references, and exploit status.

33 CVEsRSS

CVE-2026-93991High· 7.7
3d ago

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. A…

Twilightargoproj · argo-workflowsEPSS 0.33%via NVD
CVE-2026-54526High
1mo ago

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.36%via GHSA
CVE-2026-45738High· 7.3
2mo ago

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rende…

Twilightargoproj · argo_cdEPSS 0.61%via NVD
CVE-2026-45737Medium· 6.3
2mo ago

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configura…

Sunlitargoproj · argo_cdEPSS 0.52%via NVD
CVE-2026-42880Critical· 9.6PoC
4mo ago

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

Abyssalargoproj · github.com/argoproj/argo-cd/v3EPSS 0.51%via OSV
CVE-2026-42294High· 7.5
4mo ago

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

Twilightargoproj · github.com/argoproj/argo-workflows/v3EPSS 0.61%via OSV
CVE-2026-42295High
4mo ago

Argo vulnerable to exposure of artifact repository credentials

Argo vulnerable to exposure of artifact repository credentials

Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.36%via OSV
CVE-2026-40886High· 7.7
5mo ago

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.38%via OSV
CVE-2026-28229High· 7.5
6mo ago

Unauthorized access to Argo Workflows Template

Unauthorized access to Argo Workflows Template

Twilightargoproj · github.com/argoproj/argo-workflows/v3EPSS 0.65%via OSV
CVE-2026-31892High
6mo ago

Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode

Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode

Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.49%via OSV
CVE-2026-23960Medium· 5.4
8mo ago

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbit…

Sunlitargoproj · argo_workflowsEPSS 0.40%via NVD
CVE-2025-47933Critical· 9.0
1y ago

Argo CD allows cross-site scripting on repositories page

Argo CD allows cross-site scripting on repositories page

Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.46%via OSV
CVE-2025-23216Medium· 6.8
1y ago

Argo CD does not scrub secret values from patch errors

Argo CD does not scrub secret values from patch errors

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.47%via OSV
GHSA-274v-mgcv-cm8jMedium· 6.8
1y ago

Argo CD GitOps Engine does not scrub secret values from patch errors

Argo CD GitOps Engine does not scrub secret values from patch errors

Sunlitargoproj · github.com/argoproj/gitops-enginevia OSV
CVE-2024-41666Medium· 4.7
2y ago

The Argo CD web terminal session does not handle the revocation of user permissions properly

The Argo CD web terminal session does not handle the revocation of user permissions properly

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.69%via OSV
CVE-2024-37152Medium· 5.3PoC
2y ago

Unauthenticated Access to sensitive settings in Argo CD

Unauthenticated Access to sensitive settings in Argo CD

Twilightargoproj · github.com/argoproj/argo-cd/v2/serverEPSS 2.3%via OSV
CVE-2024-36106Medium· 4.3
2y ago

Argo-cd authenticated users can enumerate clusters by name

Argo-cd authenticated users can enumerate clusters by name

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.41%via OSV
CVE-2024-32476Medium· 6.5
2y ago

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 1.0%via OSV
CVE-2024-31990Medium· 4.8
2y ago

Argo CD's API server does not enforce project sourceNamespaces

Argo CD's API server does not enforce project sourceNamespaces

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.45%via OSV
CVE-2024-29893Medium· 6.5
2y ago

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.97%via OSV
CVE-2024-21661High· 7.5
2y ago

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Twilightargoproj · github.com/argoproj/argo-cdEPSS 1.2%via OSV
CVE-2024-21652Medium· 5.4
2y ago

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.75%via OSV
CVE-2024-28175Critical· 9.0
2y ago

Cross-site scripting on application summary component

Cross-site scripting on application summary component

Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.65%via OSV
CVE-2023-50726Medium· 6.4
2y ago

Users with `create` but not `override` privileges can perform local sync

Users with `create` but not `override` privileges can perform local sync

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.53%via OSV
CVE-2024-22424High· 8.3
2y ago

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

Twilightargoproj · github.com/argoproj/argo-cdEPSS 0.39%via OSV
CVE-2023-40026Medium· 5.0
2y ago

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.50%via OSV
CVE-2022-41354Medium· 5.3
3y ago

Argo CD authenticated but unauthorized users may enumerate Application names via the API

Argo CD authenticated but unauthorized users may enumerate Application names via the API

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.64%via OSV
CVE-2023-23947Critical· 9.1
3y ago

Users with any cluster secret update access may update out-of-bounds cluster secrets

Users with any cluster secret update access may update out-of-bounds cluster secrets

Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.67%via OSV
CVE-2023-22736High· 8.5
3y ago

Controller reconciles apps outside configured namespaces when sharding is enabled

Controller reconciles apps outside configured namespaces when sharding is enabled

Twilightargoproj · github.com/argoproj/argo-cd/v2EPSS 0.78%via OSV
CVE-2022-25856High· 7.5
4y ago

Insecure path traversal in Git Trigger Source can lead to arbitrary file read

Insecure path traversal in Git Trigger Source can lead to arbitrary file read

Twilightargoproj · github.com/argoproj/argo-eventsEPSS 1.9%via OSV
argoproj vulnerabilities (CVEs) · VulnSea