VYPR
Medium severity6.3GHSA Advisory· Published Jul 15, 2026· Updated Jul 20, 2026

CVE-2026-45737

CVE-2026-45737

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation because HideSecretData(target, live, ...) does not fully sanitize ResourceDiff.TargetState and LiveState predicted live Secret objects, allowing sensitive data, stringData, and annotations to appear in UI or CLI diffs. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/argoproj/argo-cd/v3Go
>= 3.2.0, < 3.2.123.2.12
github.com/argoproj/argo-cd/v3Go
>= 3.3.0-rc1, < 3.3.103.3.10
github.com/argoproj/argo-cd/v3Go
>= 3.4.0-rc1, < 3.4.23.4.2

Affected products

7

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.