Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Argoproj

First CVE: Apr 8, 2020Active for: 6 yearsTotal CVEs: 74
49.0
VTI Score
High

Argoproj maintains a tightly focused set of continuous-deployment and workflow-automation tools for Kubernetes environments, which despite limited product breadth sit prominently in modern CI/CD and infrastructure-automation pipelines. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in flagship products such as Argo CD and Argo Workflows. The exposure recurs through a pattern of information-disclosure, authorization, and input-handling weaknesses—including credential leakage, access-control flaws, cross-site scripting, and path traversal—that are characteristic of applications managing sensitive deployment configurations and cluster access. Defenders should treat updates to these products as high-priority given their role in controlling infrastructure changes and their frequent position at the cluster boundary. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
74
Total CVEs
More Total CVEs than 99% of tracked vendors
5.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Argoproj over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2020
6 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (74 CVEs).

74 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-55190CRITICAL
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.
Sep 4, 20259.951NOYES
CVE-2026-42880CRITICAL
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-
May 7, 20269.642NONO
CVE-2026-43824CRITICAL
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
May 2, 20269.642NONO
CVE-2026-42297HIGH
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's Conf
May 9, 20268.336NONO
CVE-2026-42296HIGH
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow per
May 9, 20268.135NONO
CVE-2026-45738HIGH
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argopr
Jul 15, 20268.733NONO
CVE-2026-42294HIGH
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads t
May 9, 20267.532NONO
CVE-2024-37152HIGH
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoi
Jun 6, 20247.532NOYES
CVE-2022-29165CRITICAL
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions
May 20, 202210.032NONO
CVE-2026-31892HIGH
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workfl
Mar 11, 20268.131NONO
View all 74 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products74 CVEs
47%
41%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.4%)
Network71 (95.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (2.7%)
Attack Complexity
Low67 (90.5%)
High7 (9.5%)
Unknown0 (0.0%)
User Interaction
None62 (83.8%)
Unknown0 (0.0%)
Required12 (16.2%)
Privileges Required
Low45 (60.8%)
High4 (5.4%)
None25 (33.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (74 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
2.7% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Argoproj.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Argoproj — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Argoproj's Products

View all 5 CNAs →

Top CWEs