CVE-2024-47827: Argoproj Argo Workflows

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to a race condition in a global variable in 3.6.0-rc1, the argo workflows controller can be made to crash on-command by any user with access to execute a workflow. This vulnerability is fixed in 3.6.0-rc2.

Affected products

  • Argoproj Argo Workflows: version 3.6.0 only

Published 2024-10-28. Last modified 2026-06-17.