CVE-2026-43824: Argoproj Argo Cd

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

Affected products

  • Argoproj Argo Cd: from 3.2.0, before 3.2.11 (fixed in 3.2.11); from 3.3.0, before 3.3.9 (fixed in 3.3.9)
  • Red Hat Red Hat Openshift Data Foundation 4
  • Red Hat Red Hat Openshift Gitops

Published 2026-05-02. Last modified 2026-07-15.