CVE-2026-45737
MEDIUMArgo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
Title source: cnaDescription
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation because HideSecretData(target, live, ...) does not fully sanitize ResourceDiff.TargetState and LiveState predicted live Secret objects, allowing sensitive data, stringData, and annotations to appear in UI or CLI diffs. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.
References (8)
Core 8
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/argoproj/argo-cd/security/advisories/GHSA-rg3g-4rw9-gqrp
X_Refsource_Misc x_refsource_misc
https://github.com/argoproj/argo-cd/commit/7879e6322465080a82d152bf00f2b92e0f36c658
X_Refsource_Misc x_refsource_misc
https://github.com/argoproj/argo-cd/commit/87e9148320749693624d08e3d6fa2cc217c672a0
X_Refsource_Misc x_refsource_misc
https://github.com/argoproj/argo-cd/commit/ac11bec9986807adc8886ef1181eced7347ef5c6
X_Refsource_Misc x_refsource_misc
https://github.com/argoproj/argo-cd/commit/bcb4298afc9fcff5f5d69f4e1db2d0a75983f42c
X_Refsource_Misc x_refsource_misc
https://github.com/argoproj/argo-cd/releases/tag/v3.2.12
X_Refsource_Misc x_refsource_misc
https://github.com/argoproj/argo-cd/releases/tag/v3.3.10
X_Refsource_Misc x_refsource_misc
https://github.com/argoproj/argo-cd/releases/tag/v3.4.2
Scores
CVSS v3
6.3
EPSS
0.0036
EPSS Percentile
28.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
CWE-212
Status
published
Products (4)
argoproj/argo-cd
>= 3.2.0, < 3.2.12
argoproj/argo-cd
>= 3.3.9, < 3.3.10
argoproj/argo-cd
>= 3.4.1, < 3.4.2
argoproj/argo_cd
3.2.0 - 3.2.12
Published
Jul 15, 2026
Tracked Since
Jul 16, 2026