pkg:Go/github.com/argoproj/argo-workflows/v3
22 total CVEsHIGH9MEDIUM4
✅ Check your installed version
All known vulnerabilities
- HIGH8.1CVE-2026-42296Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Securefrom 0, < 3.7.14
- >= 3.7.0, < 3.7.5
- from 0, < 3.6.14, >= 3.7.0, < 3.7.5
- HIGH8.1CVE-2025-62156argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwritefrom 0, < 3.6.12
- HIGH8.1CVE-2025-62156argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwritefrom 0, < 3.6.12, >= 3.7.0, < 3.7.3
- HIGH7.7CVE-2026-40886Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller>= 3.7.0, < 3.7.14
- >= 3.7.0, < 3.7.11
- from 0, < 3.7.11
- >= 2.6.0, < 3.2.11
- MEDIUM6.5CVE-2021-37914Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows>= 3.1.0, < 3.1.6
- MEDIUM6.5CVE-2021-37914Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows>= 3.1.0, < 3.1.6
- MEDIUM5.7CVE-2024-47827Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows>= 3.6.0-rc1, < 3.6.0-rc2
- MEDIUM5.7CVE-2024-47827Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows>= 3.6.0-rc1, < 3.6.0-rc2
- from 0, < 3.7.14
- from 0, < 3.7.11
- from 0, < 3.7.11
- from 0, < 3.6.17, >= 3.7.0, < 3.7.8
- from 0, < 3.6.17
- from 0, < 3.6.12, >= 3.7.0, < 3.7.3
- >= 3.7.0, < 3.7.3
- >= 3.5.7, < 3.5.13, >= 3.6.0-rc1, < 3.6.2
- >= 3.5.7, < 3.5.13