Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-5072"
}