Repository Credentials Race Condition Crashes Argo CD Server
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain a race condition in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same repository URL. The vulnerability is located in numerous repository related handlers in the util/db/repository_secrets.go file. A valid API token with repositories resource permissions (create, update, or delete actions) is required to trigger the race condition. This vulnerability causes the entire Argo CD server to crash and become unavailable. Attackers can repeatedly and continuously trigger the race condition to maintain a denial-of-service state, disrupting all GitOps operations. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/argoproj/argo-cd/v2Go | >= 2.1.0, < 2.14.20 | 2.14.20 |
github.com/argoproj/argo-cd/v3Go | >= 3.2.0-rc1, < 3.2.0-rc2 | 3.2.0-rc2 |
github.com/argoproj/argo-cd/v3Go | >= 3.1.0-rc1, < 3.1.8 | 3.1.8 |
github.com/argoproj/argo-cd/v3Go | >= 3.0.0-rc1, < 3.0.19 | 3.0.19 |
Affected products
10- osv-coords9 versionspkg:apk/chainguard/argo-cd-2.13-repo-serverpkg:apk/chainguard/argo-cd-fips-2.13-repo-serverpkg:apk/wolfi/argo-cd-2.13-repo-serverpkg:bitnami/argo-cdpkg:golang/github.com/argoproj/argo-cd/v2pkg:golang/github.com/argoproj/argo-cd/v3pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6
< 2.13.9-r2+ 8 more
- (no CPE)range: < 2.13.9-r2
- (no CPE)range: < 2.13.9-r3
- (no CPE)range: < 2.13.9-r2
- (no CPE)range: >= 2.1.0, < 2.14.20
- (no CPE)range: >= 2.1.0, < 2.14.20
- (no CPE)range: >= 3.2.0-rc1, < 3.2.0-rc2
- (no CPE)range: < 0.0.20251023T162509-150000.1.110.1
- (no CPE)range: < 0.0.20251023T162509-1.1
- (no CPE)range: < 0.0.20251023T162509-150000.1.110.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-g88p-r42r-ppp9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-55191ghsaADVISORY
- github.com/argoproj/argo-cd/commit/701bc50d01c752cad96185f848088d287a97c7b7ghsax_refsource_MISCWEB
- github.com/argoproj/argo-cd/pull/6103ghsax_refsource_MISCWEB
- github.com/argoproj/argo-cd/security/advisories/GHSA-g88p-r42r-ppp9ghsax_refsource_CONFIRMWEB
- pkg.go.dev/vuln/GO-2025-3994ghsaWEB
News mentions
0No linked articles in our index yet.