Argo Workflows
Vendor:
First CVE: Aug 3, 2021 · Active for 4 years
16
Total CVEs
More Total CVEs than 92% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Argo Workflows over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2021
4 years ago
Most Recent CVE
May 9, 2026
77 days ago
CVE Severity & Scoring
Argo Workflows16 CVEs
38%
63%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.3%)
Attack Complexity
Low14 (87.5%)
High2 (12.5%)
Unknown0 (0.0%)
User Interaction
None14 (87.5%)
Unknown0 (0.0%)
Required2 (12.5%)
Privileges Required
Low10 (62.5%)
High1 (6.3%)
None5 (31.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42297HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's Conf | May 9, 2026 | 8.3 | 36 | NO | NO |
CVE-2026-42296HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow per | May 9, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-42294HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads t | May 9, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-31892HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workfl | Mar 11, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-42183MEDIUM Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereferen | May 9, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-28229HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any c | Mar 11, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-40886HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's | Apr 23, 2026 | 7.7 | 28 | NO | NO |
CVE-2025-66626HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versions 3.7.0 through 3.7.4, contain | Dec 9, 2025 | 7.5 | 26 | NO | NO |
CVE-2026-42295MEDIUM Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the workflow executor l | May 9, 2026 | 4.9 | 25 | NO | NO |
CVE-2025-62156HIGH Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 contain a | Oct 14, 2025 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Argo Workflows
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.6.0 | 1 | 4.8 | 0.4% | 0 | 0 |