go

github.com/argoproj/argo-workflows/v4

View on go registry
17 Total advisories
17 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/argoproj/argo-workflows/v4 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-54526

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

HIGH 7.5
Go

CVE-2026-42294

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

UNKNOWN
Go

CVE-2026-42297

Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42183

Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

UNKNOWN
Go

CVE-2026-42183

Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42295

Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42295

Argo vulnerable to exposure of artifact repository credentials

UNKNOWN
Go

CVE-2026-42297

Argo has Missing Authorization in its Sync ConfigMap Provider

UNKNOWN
Go

CVE-2026-40886

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42294

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-42296

Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows

HIGH 8.1
Go

CVE-2026-42296

Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure

HIGH 7.7
Go

CVE-2026-40886

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

HIGH 7.5
Go

CVE-2026-28229

Unauthorized access to Argo Workflows Template

UNKNOWN
Go

CVE-2026-28229

Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-31892

Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows

UNKNOWN
Go

CVE-2026-31892

Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes