VendorsArgoprojargo_workflowsall versions
Vulnerabilities

Argoproj Argo Workflows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-31892
WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
Published 2026-03-11 · Modified
9.9EPSS 0.007
CVE-2026-54526
Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencing
Published 2026-07-16 · Analyzed
9.9EPSS 0.006
CVE-2026-28229
Argo Workflows has unauthorized access to Argo Workflows Template
Published 2026-03-11 · Modified
9.8EPSS 0.008
CVE-2025-62156
argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite
Published 2025-10-14 · Analyzed
8.8EPSS 0.006
CVE-2026-42297
Argo Workflows Is Missing Authorization in Sync ConfigMap Provider
Published 2026-05-09 · Modified
8.5EPSS 0.005
CVE-2025-62157
Argo Workflows exposes artifact repository credentials in workflow-controller logs
Published 2025-10-14 · Analyzed
8.5EPSS 0.005
CVE-2026-42295
Argo Workflows: Exposure of artifact repository credentials
Published 2026-05-09 · Analyzed
8.5EPSS 0.004
CVE-2026-42294
Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
Published 2026-05-09 · Modified
8.2EPSS 0.007
CVE-2025-66626
argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links
Published 2025-12-09 · Analyzed
8.1EPSS 0.007
CVE-2026-42296
Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
Published 2026-05-09 · Modified
8.1EPSS 0.005
CVE-2026-40886
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
Published 2026-04-23 · Modified
7.7EPSS 0.006
CVE-2024-53862
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode
Published 2024-12-02 · Analyzed
7.5EPSS 0.007
CVE-2026-23960
Argo Workflows affected by stored XSS in the artifact directory listing
Published 2026-01-21 · Modified
7.3EPSS 0.004
CVE-2022-29164
Privilege Escalation in argo-workflows
Published 2022-05-05 · Modified
7.1EPSS 0.009
CVE-2021-37914
In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.
Published 2021-08-02 · Analyzed
6.5EPSS 0.010
CVE-2026-42183
Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)
Published 2026-05-09 · Analyzed
6.5EPSS 0.006
CVE-2024-47827
Argo Workflows Controller: Denial of Service via malicious daemon Workflows
Published 2024-10-28 · Analyzed
5.7EPSS 0.004