CVE-2026-28229

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/03/2026
Last modified:
20/03/2026

Description

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:* 3.7.0 (including) 3.7.11 (excluding)
cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:* 4.0.0 (including) 4.0.2 (excluding)