Skip to main content

Vendor/product archive

argoproj / argo_cd CVEs

Beta · best-effort

57 CVEs tagged to argoproj / argo_cd12 Critical, 18 High, 26 Medium, 1 Low, 0 Unrated.

CVE-2026-45738

Published Jul 15, 2026

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argop…

CVSS 7.3 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-45737

Published Jul 15, 2026

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values em…

CVSS 6.3 · Medium
evidence mentions
8
Buzz score
27.0
Vendor/product tagsBeta · best-effort

CVE-2026-42880

Published May 7, 2026

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data…

CVSS 9.6 · Critical
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2025-59538

Published Oct 1, 2025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59537

Published Oct 1, 2025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 ar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59531

Published Oct 1, 2025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 ar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55191

Published Sep 30, 2025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 cont…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55190

Published Sep 4, 2025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-47933

Published May 29, 2025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-23216

Published Jan 30, 2025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-41666

Published Jul 24, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows users to get a shell inside a running pod, just as they woul…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40634

Published Jul 22, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a spe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37152

Published Jun 6, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36106

Published Jun 6, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s al…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31989

Published May 21, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged pod in a different namespace on the same cluster could connec…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-32476

Published May 14, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerabilit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31990

Published Apr 15, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit res…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29893

Published Mar 29, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21662

Published Mar 18, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21661

Published Mar 18, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a critical flaw in the application t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21652

Published Mar 18, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, includin…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-28175

Published Mar 13, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotatio…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-50726

Published Mar 13, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manife…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22424

Published Jan 19, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server req…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40026

Published Sep 27, 2023

Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at least in v0.1.0, but likely in any version using Helm before…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 57 CVEsPage 1 of 3