VDB
KO

GO-2026-5072

Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows

Details

Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/argoproj/argo-workflows
Introduced in: 0

No fixed version published yet for github.com/argoproj/argo-workflows (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/argoproj/argo-workflows/v2
Introduced in: 0

No fixed version published yet for github.com/argoproj/argo-workflows/v2 (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/argoproj/argo-workflows/v3
Introduced in: 0 Fixed in: 3.7.14
Fix go get github.com/argoproj/argo-workflows/v3@v3.7.14
Go / github.com/argoproj/argo-workflows/v4
Introduced in: 4.0.0 Fixed in: 4.0.5
Fix go get github.com/argoproj/argo-workflows/v4@v4.0.5

References