Delivery
Argo CD: what changed
In the last 90 days, 10 summarized changes: 10 releases. Stackdiff reads Argo CD's own feeds (argo-cd.readthedocs.io) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .
Latest changes
Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.
3.5.2Release
stable: chore: bump version to 3.5.2 on release-3.5 branch (#29404)
3.2.12Securitymedium
GHSA-h98r-wv3h-fr38: Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
3.2.12Securitymedium
GHSA-h98r-wv3h-fr38: Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
3.2.12Securitymedium
GHSA-rg3g-4rw9-gqrp: Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
3.2.11Securitymedium
GHSA-3v3m-wc6v-x4x3: ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
2.14.20Securitymedium
GO-2025-3994: Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd
2.14.20Securitymedium
GO-2025-3994: Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd
2.14.20Securitymedium
GHSA-g88p-r42r-ppp9: Repository Credentials Race Condition Crashes Argo CD Server
2.14.20Securitymedium
GHSA-g88p-r42r-ppp9: Repository Credentials Race Condition Crashes Argo CD Server
2.13.9Securitymedium
GHSA-786q-9hcg-v9ff: Argo CD's Project API Token Exposes Repository Credentials
2.13.9Securitymedium
GHSA-786q-9hcg-v9ff: Argo CD's Project API Token Exposes Repository Credentials
2.13.8Securitymedium
GHSA-2hj5-g64g-fp6p: Argo CD allows cross-site scripting on repositories page
2.13.8Securitymedium
GHSA-2hj5-g64g-fp6p: Argo CD allows cross-site scripting on repositories page
2.11.13Securitymedium
GHSA-47g2-qmh2-749v: Argo CD does not scrub secret values from patch errors
2.10.15Securityhigh
GHSA-jmvp-698c-4x3w: Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint
2.10.10Securityhigh
GHSA-9766-5277-j5hr: ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache
2.10.4Securitycritical
GHSA-6v85-wr92-q4p7: Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
2.10-rc2Securitymedium
GHSA-92mw-q256-5vwg: github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
2.3.0Securitymedium
GHSA-6jqw-jwf5-rp8h: Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
2.6.1Securitymedium
GHSA-mv6w-j4xc-qpfw: Argo CD leaks repository credentials in user-facing error messages and in logs
2.5.8Securitymedium
GHSA-6p4m-hw2h-6gmw: Controller reconciles apps outside configured namespaces when sharding is enabled
Where Stackdiff reads Argo CD
- endoflife.date
- GitHub releases · argoproj/argo-cd
- Hacker News
- OSV advisories · github.com/argoproj/argo-cd/v2
- OSV advisories · github.com/argoproj/argo-cd/v3
Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.
Get Argo CD changes in your Monday brief
Add Argo CD and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.
Get your first brief →