CVE-2026-28229: Argoproj Argo Workflows

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.

Affected products

  • Argoproj Argo Workflows: from 3.7.0, before 3.7.11 (fixed in 3.7.11); from 4.0.0, before 4.0.2 (fixed in 4.0.2)

Published 2026-03-11. Last modified 2026-07-15.