Where
-Infinity
0

Argo CD 3.4End of life details

First published (updated )

Argo CD 3.3End of life details

First published (updated )

Argo CD 3.2End of life details

First published (updated )

Argo CD 3.1Reached end of life

EOL
May 5, 2026
First published (updated )

Red Hat Red Hat OpenShift GitOpsImportant: Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Argo CD 3.0Reached end of life

EOL
Feb 2, 2026
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD does not scrub secret values from patch errors

Risk 27
Severity
6.8
EPSS
0.04%
First published (updated )

go/github.com/argoproj/argo-cd/v2The Argo CD web terminal session does not handle the revocation of user permissions properly.

Risk 40
Severity
6.5
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint

Risk 45
Severity
7.5
First published (updated )

go/github.com/argoproj/argo-cd/v2/serverUnauthenticated Access to sensitive settings in Argo CD

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/argoproj/argo-cdArgo CD allows authenticated users to enumerate clusters by name

Risk 23
Severity
4.3
First published (updated )

go/github.com/argoproj/argo-cd/v2ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache

Risk 80
Severity
9.1
First published (updated )

go/github.com/argoproj/argo-cd/v2Denial of Service via malicious jqPathExpressions in ignoreDifferences

Risk 28
Severity
6.5
EPSS
0.04%
First published (updated )

go/github.com/argoproj/argo-cd/v2Cross-site scripting on application summary component in argo-cd

Risk 57
Severity
9.1
EPSS
0.04%
First published (updated )

go/github.com/argoproj/argo-cd/v2Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/argoproj/argo-cd/v2Denial of Service to Argo CD repo-server

Risk 39
Severity
6.5
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD web terminal session doesn't expire

Risk 50
Severity
7.1
First published (updated )

go/github.com/argoproj/argo-cd/v2Cluster secret might leak in cluster details page in Argo CD

Risk 81
Severity
9.9
First published (updated )

linuxfoundation Argo Continuous Delivery KubernetesArgo CD leaks repository credentials in user-facing error messages and in logs

Risk 40
Severity
6.5
First published (updated )

Argo Argo CDAll Argo CD versions starting with v2.3.0-rc1 are vulnerable to an improper authorization bug which …

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

argoproj Argo CDArgo CD users with any cluster secret update access may update out-of-bounds cluster secrets

Risk 75
Severity
9.1
First published (updated )

argoproj Argo CDargo-cd Controller reconciles apps outside configured namespaces when sharding is enabled

Risk 73
Severity
8.6
First published (updated )

argoproj Argo CDJWT audience claim is not verified

Risk 78
Severity
9.1
First published (updated )

argoproj Argo CDCross-site Scripting for Argo CD single sign on users

Risk 38
Severity
6.1
First published (updated )

linuxfoundation Argo-cdArgo CD's certificate verification is skipped for connections to OIDC providers

Risk 80
Severity
9.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

argoproj Argo CDAll unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control …

Risk 78
Severity
9
First published (updated )

argoproj Argo CDSymlink following allows leaking out-of-bounds YAML files from Argo CD repo-server

Risk 22
Severity
4.3
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD vulnerable to Uncontrolled Memory Consumption

Risk 39
Severity
6.5
First published (updated )

go/github.com/argoproj/argo-cd/v2External URLs for Deployments can include javascript in argo-cd

Risk 78
Severity
9
First published (updated )

go/github.com/argoproj/argo-cd/v2Insecure entropy in argo-cd

Risk 73
Severity
8.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203