Security Advisories for github.com/argoproj/argo-workflows/v3 in go
High
3 months ago
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
go
github.com/argoproj/argo-workflows/v4, github.com/argoproj/argo-workflows/v3
High
3 months ago
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
go
github.com/argoproj/argo-workflows/v4, github.com/argoproj/argo-workflows/v3
High
3 months ago
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
go
github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows/v4
High
4 months ago
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
go
github.com/argoproj/argo-workflows, github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows/v4
High
6 months ago
Argo Workflows affected by stored XSS in the artifact directory listing
go
github.com/argoproj/argo-workflows, github.com/argoproj/argo-workflows/v3
High
8 months ago
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
go
github.com/argoproj/argo-workflows, github.com/argoproj/argo-workflows/v3
High
9 months ago
Argo Workflow may expose artifact repository credentials
go
github.com/argoproj/argo-workflows/v3
High
9 months ago
Argo Workflow has a Zipslip Vulnerability
go
github.com/argoproj/argo-workflows/v3
Moderate
over 1 year ago
Access to Archived Argo Workflows with Fake Token in `client` mode
go
github.com/argoproj/argo-workflows/v3
Moderate
over 1 year ago
Argo Workflows Controller: Denial of Service via malicious daemon Workflows
go
github.com/argoproj/argo-workflows/v3
High
about 4 years ago
Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows
go
github.com/argoproj/argo-workflows/v3
Low
almost 5 years ago
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client`
go
github.com/argoproj/argo-workflows/v3
Moderate
almost 5 years ago
Argo Server TLS requests could be forged by attacker with network access
go
github.com/argoproj/argo-workflows/v3
Moderate
almost 5 years ago
Workflow re-write vulnerability using input parameter
go
github.com/argoproj/argo-workflows/v3