Server-Side Request Forgery in Argo CD by Argo Project
CVE-2026-43824

7.7HIGH

Key Information:

Vendor

Argoproj

Status
Vendor
CVE Published:
2 May 2026

What is CVE-2026-43824?

In specific versions of Argo CD, a Server-Side Request Forgery vulnerability has been identified that allows attackers to read cleartext Kubernetes Secret data. This can lead to unauthorized access to sensitive information stored within Kubernetes, compromising the integrity and confidentiality of the cluster’s resources. Users are encouraged to apply the latest patches and updates to secure their deployments.

Affected Version(s)

Argo CD 3.2.0 < 3.2.11

Argo CD 3.3.0 < 3.3.9

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.