Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
Modified: 6/25/2026
package
pkg:go/github.com/argoproj/argo-workflows/v4
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
Modified: 6/25/2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
Modified: 9/10/2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Modified: 9/10/2026
Unauthorized access to Argo Workflows Template
Modified: 9/10/2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
Modified: 9/10/2026
Argo vulnerable to exposure of artifact repository credentials
Modified: 9/10/2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
Modified: 7/21/2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)
Modified: 9/10/2026
Argo has Missing Authorization in its Sync ConfigMap Provider
Modified: 9/10/2026
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows
Modified: 3/23/2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows
Modified: 3/23/2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows
Modified: 6/25/2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows
Modified: 6/26/2026
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows
Modified: 7/2/2026
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows
Modified: 6/25/2026
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows
Modified: 7/2/2026
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows
Modified: 7/2/2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
Modified: 8/18/2026