Security: argoproj/argo-cd
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotationsGHSA-rg3g-4rw9-gqrp published
May 13, 2026 by crenshaw-devModerate -
Stored XSS in application link annotations enables developer-to-admin privilege escalationGHSA-h98r-wv3h-fr38 published
May 13, 2026 by crenshaw-devHigh -
Kubernetes Secret Extraction via ArgoCD ServerSideDiffGHSA-3v3m-wc6v-x4x3 published
May 1, 2026 by alexmtCritical -
Project API Token Exposes Repository CredentialsGHSA-786q-9hcg-v9ff published
Sep 4, 2025 by crenshaw-devCritical -
Unauthenticated Remote DoS in Argo CD via malformed Azure DevOps git.push webhookGHSA-gpx4-37g2-c8pv published
Sep 30, 2025 by crenshaw-devHigh -
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payloadGHSA-f9gq-prrc-hrhc published
Sep 30, 2025 by crenshaw-devHigh -
Unauthenticated DoS via malformed Gogs webhook payloadGHSA-wp4p-9pxh-cgx2 published
Sep 30, 2025 by crenshaw-devHigh -
DoS via credentials updates triggering a race condition that crashes the Argo CD serverGHSA-g88p-r42r-ppp9 published
Sep 30, 2025 by crenshaw-devModerate -
The Argo CD web terminal session does not handle the revocation of user permissions properly.GHSA-v8wx-v5jq-qhhw published
Jul 24, 2024 by pasha-codefreshModerate -
Denial of Service via malicious jqPathExpressions in ignoreDifferencesGHSA-9m6p-x4h2-6frq published
Apr 26, 2024 by pasha-codefreshModerate