CVE Tools

Argo Workflows

17 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Argo Workflows, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Argo Workflows CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Argo Workflows CVEs per month
MonthCVEs
2024-101
2024-110
2024-121
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-102
2025-110
2025-121
2026-011
2026-020
2026-032
2026-041
2026-055
2026-060
2026-071
2026-080
2026-090

Severity

How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical212%
  • High953%
  • Medium635%

Latest CVEs

The 15 most recently published vulnerabilities affecting Argo Workflows.

  1. CVE-2026-54526Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencing9.9
  2. CVE-2026-42296Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure8.1
  3. CVE-2026-42295Argo Workflows: Exposure of artifact repository credentials4.9
  4. CVE-2026-42294Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor7.5
  5. CVE-2026-42183Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)6.5
  6. CVE-2026-42297Argo Workflows Is Missing Authorization in Sync ConfigMap Provider8.3
  7. CVE-2026-40886Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller7.7
  8. CVE-2026-31892WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode8.1
  9. CVE-2026-28229Argo Workflows has unauthorized access to Argo Workflows Template9.8
  10. CVE-2026-23960Argo Workflows affected by stored XSS in the artifact directory listing5.4
  11. CVE-2025-66626argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links8.1
  12. CVE-2025-62157Argo Workflows exposes artifact repository credentials in workflow-controller logs6.5
  13. CVE-2025-62156argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite8.1
  14. CVE-2024-53862Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode7.5
  15. CVE-2024-47827Argo Workflows Controller: Denial of Service via malicious daemon Workflows5.7

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store