CVE-2025-55191

MEDIUM

Argo CD <2.14.19, 3.1.7, 3.0.18 - Info Disclosure

Title source: llm
STIX 2.1

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain a race condition in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same repository URL. The vulnerability is located in numerous repository related handlers in the util/db/repository_secrets.go file. A valid API token with repositories resource permissions (create, update, or delete actions) is required to trigger the race condition. This vulnerability causes the entire Argo CD server to crash and become unavailable. Attackers can repeatedly and continuously trigger the race condition to maintain a denial-of-service state, disrupting all GitOps operations. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362
Status published
Products (4)
argoproj/argo-cd 2.1.0 - 2.14.20Go
argoproj/argo-cd 3.2.0-rc1 - 3.2.0-rc2Go
argoproj/argo_cd 3.2.0 rc1
argoproj/argo_cd 2.1.0 - 2.14.20
Published Sep 30, 2025
Tracked Since Feb 18, 2026