CVE Tools

Argo Cd

58 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Argo Cd, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Argo Cd CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Argo Cd CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-011
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-092
2025-103
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-052
2026-060
2026-072
2026-080
2026-090

Severity

How the 58 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1221%
  • High1933%
  • Medium2645%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Argo Cd.

  1. CVE-2026-45737Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations6.3
  2. CVE-2026-45738Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation7.3
  3. CVE-2026-42880ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction9.6
  4. CVE-2026-43824In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.7.7
  5. CVE-2025-59538Argo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook7.5
  6. CVE-2025-59537argo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payload7.5
  7. CVE-2025-59531Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload7.5
  8. CVE-2025-55191Repository Credentials Race Condition Crashes Argo CD Server6.5
  9. CVE-2025-55190Argo CD: Project API Token Exposes Repository Credentials9.9
  10. CVE-2025-47933Argo CD allows cross-site scripting on repositories page9.0
  11. CVE-2025-23216Argo CD does not scrub secret values from patch errors6.8
  12. CVE-2024-41666The Argo CD web terminal session does not handle the revocation of user permissions properly.4.7
  13. CVE-2024-40634Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint7.5
  14. CVE-2024-37152Unauthenticated Access to sensitive settings in Argo CD5.3
  15. CVE-2024-36106Argo CD allows authenticated users to enumerate clusters by name4.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store