CVE-2026-42183

medium
Published 2026-05-09 · Modified 2026-05-13
CVSS v3
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk
6.5

Description

Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/argoproj/argo-workflows/security/advisories/GHSA-p4gq-3vxj-f4jq

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/argoproj/argo-workflows/releases/tag/v4.0.5

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/argoproj/argo-workflows/commit/c4cc17d0c034fa9a9cc01ef1af6c8016c93071d4

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/argoproj/argo-workflows/v4>=4.0.0,<4.0.54.0.5
golang GOgithub.com/argoproj/argo-workflows/v4>= 4.0.0, <= 4.0.44.0.5

Application impact

VendorProductVersionsFixed
argoprojargo_workflows{"startIncluding":"4.0.0","endExcluding":"4.0.5"}4.0.5

References

CWEs

CWE-476

Verify integrity in audit chain (admin only). AS-IS.