VDB
KO

GO-2026-6223

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

Quick fix

GO-2026-6223 — github.com/argoproj/argo-workflows/v3: upgrade to the fixed version with the command below.

go get github.com/argoproj/argo-workflows/v3@v3.7.15

Details

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/argoproj/argo-workflows
Introduced in: 0

No fixed version published yet for github.com/argoproj/argo-workflows (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/argoproj/argo-workflows/v2
Introduced in: 0

No fixed version published yet for github.com/argoproj/argo-workflows/v2 (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/argoproj/argo-workflows/v3
Introduced in: 0 Fixed in: 3.7.15
Fix go get github.com/argoproj/argo-workflows/v3@v3.7.15
Go / github.com/argoproj/argo-workflows/v4
Introduced in: 4.0.0 Fixed in: 4.0.6
Fix go get github.com/argoproj/argo-workflows/v4@v4.0.6

References