Argoproj maintains a tightly focused set of continuous-deployment and workflow-automation tools for Kubernetes environments, which despite limited product breadth sit prominently in modern CI/CD and infrastructure-automation pipelines. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in flagship products such as Argo CD and Argo Workflows. The exposure recurs through a pattern of information-disclosure, authorization, and input-handling weaknesses—including credential leakage, access-control flaws, cross-site scripting, and path traversal—that are characteristic of applications managing sensitive deployment configurations and cluster access. Defenders should treat updates to these products as high-priority given their role in controlling infrastructure changes and their frequent position at the cluster boundary. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Argoproj over time
Signals from CVEs in this vendor scope (74 CVEs).
74 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55190CRITICAL Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1. | Sep 4, 2025 | 9.9 | 51 | NO | YES |
CVE-2026-42880CRITICAL Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data- | May 7, 2026 | 9.6 | 42 | NO | NO |
CVE-2026-43824CRITICAL In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. | May 2, 2026 | 9.6 | 42 | NO | NO |
CVE-2026-42297HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's Conf | May 9, 2026 | 8.3 | 36 | NO | NO |
CVE-2026-42296HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow per | May 9, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-45738HIGH Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argopr | Jul 15, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-42294HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads t | May 9, 2026 | 7.5 | 32 | NO | NO |
CVE-2024-37152HIGH Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoi | Jun 6, 2024 | 7.5 | 32 | NO | YES |
CVE-2022-29165CRITICAL Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions | May 20, 2022 | 10.0 | 32 | NO | NO |
CVE-2026-31892HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workfl | Mar 11, 2026 | 8.1 | 31 | NO | NO |
Signals from CVEs in this vendor scope (74 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Argoproj.
Media articles that mention a CVE ID that affects a product developed by Argoproj — matched by CVE ID, not by vendor name.