VendorsArgoprojargo_cdany version
Vulnerabilities

Argoproj Argo Project Argo CD any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

55CVEs
CVE-2022-29165
Argo CD will blindly trust JWT claims if anonymous access is enabled
Published 2022-05-20 · Modified
10.0EPSS 0.021
CVE-2025-55190
Argo CD: Project API Token Exposes Repository Credentials
Published 2025-09-04 · Analyzed
9.9EPSS 0.055
CVE-2022-24768
Improper access control allows admin privilege escalation in Argo CD
Published 2022-03-23 · Modified
9.9EPSS 0.013
CVE-2023-40029
Cluster secret might leak in cluster details page in Argo CD
Published 2023-09-07 · Modified
9.9EPSS 0.012
CVE-2024-21652
Argo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data Loss
Published 2024-03-18 · Analyzed
9.8EPSS 0.008
CVE-2022-31105
Argo CD's certificate verification is skipped for connections to OIDC providers
Published 2022-07-12 · Modified
9.6EPSS 0.008
CVE-2026-42880
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
Published 2026-05-07 · Modified
9.6EPSS 0.006
CVE-2024-21662
Argo CD vulnerable to Bypassing of Rate Limit and Brute Force Protection Using Cache Overflow
Published 2024-03-18 · Analyzed
9.1EPSS 0.008
CVE-2023-23947
Argo CD users with any cluster secret update access may update out-of-bounds cluster secrets
Published 2023-02-16 · Modified
9.1EPSS 0.007
CVE-2024-31989
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache
Published 2024-05-21 · Analyzed
9.0EPSS 0.015
CVE-2022-1025
All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
Published 2022-07-12 · Modified
9.0EPSS 0.013
CVE-2022-31035
External URLs for Deployments can include javascript in argo-cd
Published 2022-06-27 · Modified
9.0EPSS 0.010
CVE-2023-22482
JWT audience claim is not verified
Published 2023-01-25 · Modified
9.0EPSS 0.009
CVE-2024-28175
Cross-site scripting on application summary component in argo-cd
Published 2024-03-13 · Analyzed
9.0EPSS 0.007
CVE-2025-47933
Argo CD allows cross-site scripting on repositories page
Published 2025-05-29 · Analyzed
9.0EPSS 0.005
CVE-2020-8828
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.
Published 2020-04-08 · Modified
8.8EPSS 0.018
CVE-2026-45738
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
Published 2026-07-15 · Analyzed
8.7EPSS 0.006
CVE-2023-22736
argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled
Published 2023-01-26 · Modified
8.5EPSS 0.008
CVE-2022-31034
Insecure entropy in argo-cd
Published 2022-06-27 · Modified
8.3EPSS 0.009
CVE-2024-22424
Cross-Site Request Forgery (CSRF) in github.com/argoproj/argo-cd
Published 2024-01-19 · Modified
8.3EPSS 0.004
CVE-2022-24348
Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.
Published 2022-02-04 · Modified
7.7EPSS 0.027
CVE-2022-24730
Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server
Published 2022-03-23 · Modified
7.7EPSS 0.009
CVE-2025-59538
Argo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
Published 2025-10-01 · Analyzed
7.5EPSS 0.089
CVE-2024-37152
Unauthenticated Access to sensitive settings in Argo CD
Published 2024-06-06 · Modified
7.5EPSS 0.023
CVE-2020-8827
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.
Published 2020-04-08 · Modified
7.5EPSS 0.022
CVE-2020-8826
As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.
Published 2020-04-08 · Modified
7.5EPSS 0.017
CVE-2021-26923
An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authentication.
Published 2021-03-15 · Modified
7.5EPSS 0.014
CVE-2024-40634
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint
Published 2024-07-22 · Analyzed
7.5EPSS 0.014
CVE-2024-21661
Argo CD Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
Published 2024-03-18 · Analyzed
7.5EPSS 0.012
CVE-2025-59537
argo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payload
Published 2025-10-01 · Analyzed
7.5EPSS 0.006
CVE-2025-59531
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
Published 2025-10-01 · Analyzed
7.5EPSS 0.006
CVE-2023-40025
Argo CD web terminal session doesn't expire
Published 2023-08-23 · Modified
7.1EPSS 0.006
CVE-2022-24731
Path traversal allows leaking out-of-bound files from Argo CD repo-server
Published 2022-03-23 · Modified
6.8EPSS 0.010
CVE-2025-23216
Argo CD does not scrub secret values from patch errors
Published 2025-01-30 · Analyzed
6.8EPSS 0.005
CVE-2023-40584
Denial of Service to Argo CD repo-server
Published 2023-09-07 · Modified
6.5EPSS 0.014
CVE-2018-21034
In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other manifests which were stored within git.
Published 2020-04-09 · Modified
6.5EPSS 0.014
CVE-2021-26921
In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.
Published 2021-02-09 · Modified
6.5EPSS 0.013
CVE-2024-32476
Denial of Service via malicious jqPathExpressions in ignoreDifferences
Published 2024-04-26 · Analyzed
6.5EPSS 0.010
CVE-2024-29893
Uncontrolled Resource Consumption vulnerability in ArgoCD's repo server
Published 2024-03-29 · Analyzed
6.5EPSS 0.010
CVE-2022-31016
Argo CD vulnerable to Uncontrolled Memory Consumption
Published 2022-06-25 · Modified
6.5EPSS 0.009
1 / 2Next →