go

github.com/argoproj/argo-cd/v3

View on go registry
18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/argoproj/argo-cd/v3 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-42880

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd

CRITICAL 9.6
Go

CVE-2026-42880

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

HIGH 7.3
Go

CVE-2026-45738

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

MEDIUM 6.3
Go

CVE-2026-45737

Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations

UNKNOWN
Go

CVE-2026-45737

Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd

UNKNOWN
Go

CVE-2026-45738

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd

UNKNOWN
Go

CVE-2025-59531

Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd

UNKNOWN
Go

CVE-2025-59537

argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd

CRITICAL 9.9
Go

CVE-2025-55190

Argo CD's Project API Token Exposes Repository Credentials

CRITICAL 9.0
Go

CVE-2025-47933

Argo CD allows cross-site scripting on repositories page

UNKNOWN
Go

CVE-2025-55190

Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd

UNKNOWN
Go

CVE-2025-47933

Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd

HIGH 7.5
Go

CVE-2025-59538

Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook

HIGH 7.5
Go

CVE-2025-59537

argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload

HIGH 7.5
Go

CVE-2025-59531

Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload

MEDIUM 6.5
Go

CVE-2025-55191

Repository Credentials Race Condition Crashes Argo CD Server

UNKNOWN
Go

CVE-2025-55191

Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd

UNKNOWN
Go

CVE-2025-59538

Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook in github.com/argoproj/argo-cd

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes