Argo Events Project maintains a specialized event-driven automation component for Kubernetes-native CI/CD pipelines, with a narrowly scoped product footprint centered on the Argo Events platform. Its reported vulnerabilities cluster around file-system handling and resource management, including path traversal, improper link resolution, out-of-bounds writes, and uncontrolled resource consumption—issues characteristic of event-processing systems that parse inputs from diverse trigger sources and manage temporary resources. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Argo Events Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25856HIGH The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allo | Jun 17, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-31054HIGH Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the deprecated `ioutil.ReadAll()`. | Jun 13, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Argo Events Project.
Media articles that mention a CVE ID that affects a product developed by Argo Events Project — matched by CVE ID, not by vendor name.