Critical severity9.6GHSA Advisory· Published May 7, 2026· Updated Aug 11, 2026
CVE-2026-42880
CVE-2026-42880
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/argoproj/argo-cd/v3Go | >= 3.2.0, < 3.2.11 | 3.2.11 |
github.com/argoproj/argo-cd/v3Go | >= 3.3.0, < 3.3.9 | 3.3.9 |
Affected products
8- osv-coords6 versionspkg:apk/chainguard/argocd-image-updaterpkg:apk/chainguard/argocd-image-updater-fipspkg:apk/wolfi/argocd-image-updaterpkg:bitnami/argo-cdpkg:golang/github.com/argoproj/argo-cd/v3pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 1.2.0-r1+ 5 more
- (no CPE)range: < 1.2.0-r1
- (no CPE)range: < 1.2.0-r1
- (no CPE)range: < 1.2.0-r1
- (no CPE)range: >= 3.2.0, < 3.2.11
- (no CPE)range: >= 3.2.0, < 3.2.11
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
9- github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-3v3m-wc6v-x4x3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-42880ghsaADVISORY
- access.redhat.com/errata/RHBA-2026:12433nvd
- access.redhat.com/errata/RHSA-2026:20943nvd
- access.redhat.com/errata/RHSA-2026:20947nvd
- access.redhat.com/security/cve/CVE-2026-42880nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42880.jsonnvd
News mentions
1- Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes ClustersThe Hacker News · Jul 1, 2026