—
GO-2026-5462
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows
Quick fix
GO-2026-5462 — github.com/argoproj/argo-workflows/v3: upgrade to the fixed version with the command below.
go get github.com/argoproj/argo-workflows/v3@v3.7.14 Details
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/argoproj/argo-workflows
Introduced in:
0 No fixed version published yet for github.com/argoproj/argo-workflows (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/argoproj/argo-workflows/v2
Introduced in:
0 No fixed version published yet for github.com/argoproj/argo-workflows/v2 (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/argoproj/argo-workflows/v3
Introduced in:
0 Fixed in: 3.7.14 Fix
go get github.com/argoproj/argo-workflows/v3@v3.7.14 Go / github.com/argoproj/argo-workflows/v4
Introduced in:
4.0.0 Fixed in: 4.0.5 Fix
go get github.com/argoproj/argo-workflows/v4@v4.0.5 References
- https://github.com/argoproj/argo-workflows/security/advisories/GHSA-jcc8-g2q4-9fxq [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-42294 [ADVISORY]
- https://github.com/argoproj/argo-workflows/commit/7abb4de6c3599e2d5d960ba4d5de4cf1df109965 [FIX]
- https://github.com/argoproj/argo-workflows/releases/tag/v3.7.14 [WEB]
- https://github.com/argoproj/argo-workflows/releases/tag/v4.0.5 [WEB]