go

github.com/argoproj/argo-workflows/v2

View on go registry
18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/argoproj/argo-workflows/v2 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-54526

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42297

Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42183

Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42295

Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-40886

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42294

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42296

Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-28229

Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-31892

Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2024-47827

Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows

UNKNOWN
Go

GHSA-6c73-2v8x-qpvm

Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2021-37914

Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows

UNKNOWN
Go

GHSA-prqf-xr2j-xf65

Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2025-62157

Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-23960

Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2025-66626

RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2024-53862

Argo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2025-62156

Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes