Dependency scanning
Check whether github.com/argoproj/argo-workflows is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-54526
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
CVE-2026-42297
Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows
CVE-2026-42183
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows
CVE-2026-42295
Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows
CVE-2026-40886
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows
CVE-2026-42294
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows
CVE-2026-42296
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows
CVE-2026-28229
Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows
CVE-2026-31892
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows
CVE-2026-31892
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
CVE-2024-47827
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows
GHSA-6c73-2v8x-qpvm
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows
CVE-2021-37914
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows
GHSA-prqf-xr2j-xf65
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows
CVE-2025-62157
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows
CVE-2026-23960
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows
CVE-2026-23960
Argo Workflows affected by stored XSS in the artifact directory listing
CVE-2025-66626
RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows
CVE-2024-53862
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows
CVE-2025-62156
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows
CVE-2025-66626
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
GHSA-rc7p-gmvh-xfx2
Attack on Kubernetes via Misconfigured Argo Workflows
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes