VDB
Sign up
—

GO-2026-5072

Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows

Quick fix

GO-2026-5072 — github.com/argoproj/argo-workflows/v3: upgrade to the fixed version with the command below.

go get github.com/argoproj/argo-workflows/v3@v3.7.14

Details

Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/argoproj/argo-workflows
Introduced in: 0

No fixed version published yet for github.com/argoproj/argo-workflows (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/argoproj/argo-workflows/v2
Introduced in: 0

No fixed version published yet for github.com/argoproj/argo-workflows/v2 (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/argoproj/argo-workflows/v3
Introduced in: 0Fixed in: 3.7.14
Fixgo get github.com/argoproj/argo-workflows/v3@v3.7.14
Go/github.com/argoproj/argo-workflows/v4
Introduced in: 4.0.0Fixed in: 4.0.5
Fixgo get github.com/argoproj/argo-workflows/v4@v4.0.5

References