BIT-argo-workflows-2026-40886

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/argo-workflows/BIT-argo-workflows-2026-40886.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-argo-workflows-2026-40886
Aliases
Published
2026-04-25T08:35:39.954Z
Modified
2026-04-25T09:26:13.786906676Z
Summary
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
Details

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pod-gc-strategy annotation. Because the panic occurs inside an informer goroutine (outside the controller's recover() scope), it crashes the entire controller process. The poisoned pod persists across restarts, causing a crash loop that halts all workflow processing until the pod is manually deleted. This vulnerability is fixed in 4.0.5 and 3.7.14.

Database specific
{
    "cpes": [
        "cpe:2.3:a:argo_workflows_project:argo_workflows:*:*:*:*:*:kubernetes:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / argo-workflows

Package

Name
argo-workflows
Purl
pkg:bitnami/argo-workflows

Severity

  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.6.5
Fixed
3.7.14
Introduced
4.0.0
Fixed
4.0.5

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/argo-workflows/BIT-argo-workflows-2026-40886.json"