argoproj Vulnerabilities and Affected Products
Vulnerabilities associated with argo-events.
Products
Clear product- argo-cd44 vulnerabilities
- argo-workflows16 vulnerabilities
- argo-helm4 vulnerabilities
- argo-events2 vulnerabilities
- argo_cd2 vulnerabilities
- Argo CD1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-32445CRITICAL | Users can gain privileged access to the host system and cluster with EventSource and Sensor CRArgo Events is an event-driven workflow automation framework for Kubernetes. A user with permission to create/modify EventSource and Sensor custom resources can gain privileged access to the host system and cluster, even without having direct administrative privileges. The EventSource and Sensor CRs allow the corresponding orchestrated pod to be customized with spec.template and spec.template.container (with type k8s.io/api/core/v1.Container), thus, any specification under container such as comm… | CVSS10.0v3.1 | EPSS0.753% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-31054HIGH | Uses of deprecated API can be used to cause DoS in user-facing endpoints in Argo EventsArgo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the deprecated `ioutil.ReadAll()`. `ioutil.ReadAll()` reads all the data into memory. As such, an attacker who sends a large request to the Argo Events server will be able to crash it and cause denial of service. A patch for this vulnerability has been released in Argo Events version 1.7.1. | CVSS7.5v3.1 | EPSS1.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |