18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/argoproj/argo-cd/v3 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-42880
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd
CRITICAL 9.6
CVE-2026-42880
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
HIGH 7.3
CVE-2026-45738
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
MEDIUM 6.3
CVE-2026-45737
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
UNKNOWN
CVE-2026-45737
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd
UNKNOWN
CVE-2026-45738
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd
UNKNOWN
CVE-2025-59531
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd
UNKNOWN
CVE-2025-59537
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd
CRITICAL 9.9
CVE-2025-55190
Argo CD's Project API Token Exposes Repository Credentials
CRITICAL 9.0
CVE-2025-47933
Argo CD allows cross-site scripting on repositories page
UNKNOWN
CVE-2025-55190
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd
UNKNOWN
CVE-2025-47933
Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd
HIGH 7.5
CVE-2025-59538
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
HIGH 7.5
CVE-2025-59537
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload
HIGH 7.5
CVE-2025-59531
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
MEDIUM 6.5
CVE-2025-55191
Repository Credentials Race Condition Crashes Argo CD Server
UNKNOWN
CVE-2025-55191
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd
UNKNOWN
CVE-2025-59538
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes