High severity7.5NVD Advisory· Published Jun 13, 2022· Updated Jun 17, 2026
CVE-2022-31054
CVE-2022-31054
Description
Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several HandleRoute endpoints make use of the deprecated ioutil.ReadAll(). ioutil.ReadAll() reads all the data into memory. As such, an attacker who sends a large request to the Argo Events server will be able to crash it and cause denial of service. A patch for this vulnerability has been released in Argo Events version 1.7.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/argoproj/argo-eventsGo | < 1.7.1 | 1.7.1 |
Affected products
3- Range: < 1.7.1
- cpe:2.3:a:argo_events_project:argo_events:*:*:*:*:*:*:*:*Range: <1.7.1
Patches
Vulnerability mechanics
References
6- github.com/argoproj/argo-events/commit/eaabcb6d65022fc34a0cc9ea7f00681abd326b35nvdPatchThird Party AdvisoryWEB
- github.com/argoproj/argo-events/pull/1966nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5q86-62xr-3r57ghsaADVISORY
- github.com/argoproj/argo-events/issues/1946nvdIssue TrackingThird Party AdvisoryWEB
- github.com/argoproj/argo-events/security/advisories/GHSA-5q86-62xr-3r57nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-31054ghsaADVISORY
News mentions
0No linked articles in our index yet.