argo-cd9.7.1

Helm chart
argo repositoryon Artifact Hub 844#3 by starsofficialverified publisher

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

version 9.7.1kube >=1.25.0-0app version v3.4.4
README badge
[![Radar Score](https://charts.stackradar.io/badge/argo/argo-cd.svg)](https://charts.stackradar.io/charts/argo/argo-cd)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

Radar Score

3,107
worst finding Medium
Critical
0
High
0
Medium
17
Low
402
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

419 findings over 2 of 3 images measured · scored 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of 9.7.1, one sample per day, last 90 days. Hover a point for its date and advisory data.

2 Sept 2026 · Radar Score 3,107 · OSV as of 2 Sept 2026
history since 2 Sept 2026

Score moves

A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves

Fewer than two samples so far.

Findings

showing 50 of 343

AdvisoryPackageFixed inContributionEPSSSinceDigests
GHSA-5cgq-3rg8-m6cv

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

golang.org/x/crypto@v0.36.0golang0.52.038/1000.073 (94th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-2x32-jm95-2cpx

Authentication Bypass in dex

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.27.025/1000.017 (75th pct)2 Sept 20268499afd690c4
GHSA-m9hp-7r99-94h5

Critical security issues in XML encoding in github.com/dexidp/dex

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.27.024/1000.017 (75th pct)2 Sept 20268499afd690c4
GHSA-p77j-4mvh-x3m3

gRPC-Go has an authorization bypass via missing leading slash in :path

google.golang.org/grpc@v1.72.1golang1.79.323/1000.016 (73th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-vh7g-p26c-j2cw

Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.35.021/1000.012 (66th pct)2 Sept 20268499afd690c4
GHSA-x527-x647-q7gg

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

golang.org/x/crypto@v0.36.0golang0.52.017/1000.005 (41th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-vgwf-h737-ff37

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto@v0.36.0golang0.52.017/1000.006 (47th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-f5wc-c3c7-36mc

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto@v0.36.0golang0.52.017/1000.006 (46th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-pc3f-x583-g7j2

SpdyStream: DOS on CRI

github.com/moby/spdystream@v0.5.0golang0.5.116/1000.007 (49th pct)2 Sept 20262fb3efa9eaa4
GHSA-rm3j-f69w-wqmq

golang.org/x/crypto vulnerable to infinite loop on large channel writes

golang.org/x/crypto@v0.36.0golang0.52.016/1000.005 (42th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-r53h-jv2g-vpx6

Helm's Missing YAML Content Leads To Panic

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.14.216/1000.009 (58th pct)2 Sept 20262fb3efa9eaa4
GHSA-89gr-r52h-f8rx

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

golang.org/x/crypto@v0.36.0golang0.52.015/1000.004 (35th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-jppx-rxg9-jmrx

golang.org/x/crypto doesn't enforce invoking key constraints

golang.org/x/crypto@v0.36.0golang0.52.015/1000.004 (34th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-7hfp-qfw3-5jxh

Helm Vulnerable to denial of service through string value parsing

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.9.414/1000.010 (61th pct)2 Sept 20262fb3efa9eaa4
GHSA-mh2q-q3fh-2475

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

go.opentelemetry.io/otel@v1.39.0golang1.41.014/1000.007 (48th pct)2 Sept 20268499afd690c4
GHSA-78h2-9frx-2jm8

Go JOSE Panics in JWE decryption

github.com/go-jose/go-jose/v4@v4.1.3golang4.1.414/1000.007 (48th pct)2 Sept 20268499afd690c4
GHSA-56hp-xqp3-w2jf

Helm passes repository credentials to alternate domain

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.6.113/1000.014 (70th pct)2 Sept 20262fb3efa9eaa4
GHSA-557j-xg8c-q2mm

Helm vulnerable to Code Injection through malicious chart.yaml content

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.413/1000.004 (29th pct)2 Sept 20262fb3efa9eaa4
GHSA-q4h4-gmj2-qvw2

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

golang.org/x/crypto@v0.36.0golang0.52.013/1000.005 (39th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-w879-237q-wc7r

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

golang.org/x/crypto@v0.36.0golang0.52.013/1000.005 (38th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-8xwf-rjm4-xvhv

oras-go has file store write outside workingDir via symlink traversal

oras.land/oras-go/v2@v2.6.0golang2.6.112/1000.005 (41th pct)2 Sept 20262fb3efa9eaa4
GHSA-qw64-3x98-g7q2

go-billy has path traversal vulnerabilities

github.com/go-git/go-billy/v5@v5.6.2golang5.9.012/1000.003 (23th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-jxpm-75mh-9fp7

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

oras.land/oras-go/v2@v2.6.0golang2.6.112/1000.004 (31th pct)2 Sept 20262fb3efa9eaa4
GHSA-fxhp-mv3v-67qp

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

oras.land/oras-go/v2@v2.6.0golang2.6.212/1000.004 (36th pct)2 Sept 20262fb3efa9eaa4
GHSA-pjcq-xvwq-hhpj

go-ntlmssp NTLM challenges can panic on malformed payloads

github.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358golang0.1.112/1000.010 (61th pct)2 Sept 20268499afd690c4
GHSA-v53g-5gjp-272r

Helm dependency management path traversal

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.14.111/1000.006 (45th pct)2 Sept 20262fb3efa9eaa4
GHSA-hc8v-wwc9-vgxm

go-git: Worktree operations may follow symlinks

github.com/go-git/go-git/v5@v5.14.0golang5.19.211/1000.004 (29th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4341

Memory exhaustion in query parameter parsing in net/url

stdlib@go1.24.11golang1.24.1211/1000.020 (79th pct)2 Sept 20262fb3efa9eaa4
GHSA-479m-364c-43vc

validateSignature Loop Variable Capture Signature Bypass in goxmldsig

github.com/russellhaering/goxmldsig@v1.5.0golang1.6.011/1000.003 (22th pct)2 Sept 20268499afd690c4
GHSA-5xqw-8hwv-wg92

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.311/1000.005 (38th pct)2 Sept 20262fb3efa9eaa4
GHSA-53c4-hhmh-vw5q

Helm vulnerable to denial of service through through repository index file

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.311/1000.008 (54th pct)2 Sept 20262fb3efa9eaa4
GHSA-67fx-wx78-jx33

Helm vulnerable to denial of service through schema file

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.311/1000.008 (54th pct)2 Sept 20262fb3efa9eaa4
GHSA-4hfp-h4cw-hj8p

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.311/1000.004 (36th pct)2 Sept 20262fb3efa9eaa4
GHSA-6rx9-889q-vv2r

Helm vulnerable to denial of service through string value parsing

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.310/1000.008 (52th pct)2 Sept 20262fb3efa9eaa4
GHSA-xhf5-7wjv-pqxp

containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

github.com/containerd/containerd@v1.7.29golang1.7.3310/1000.002 (6th pct)2 Sept 20262fb3efa9eaa4
GHSA-m3xc-h892-ggx6

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

github.com/go-git/go-billy/v5@v5.6.2golang5.9.010/1000.004 (32th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-qgq7-7hm3-q39j

go-git: Malicious reference names may modify files outside the reference storage

github.com/go-git/go-git/v5@v5.14.0golang5.19.210/1000.004 (34th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-hfvc-g4fc-pqhx

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

go.opentelemetry.io/otel/sdk@v1.39.0golang1.43.010/1000.003 (17th pct)2 Sept 20268499afd690c4
GHSA-q9hv-hpm4-hj6x

CIRCL has an incorrect calculation in secp384r1 CombinedMult

github.com/cloudflare/circl@v1.6.1golang1.6.310/1000.004 (33th pct)2 Sept 20268499afd690c4
ALPINE-CVE-2026-31789openssl@3.5.5-r0apk3.5.6-r010/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-63073openssl@3.5.5-r0apk3.5.8-r010/1002 Sept 20268499afd690c4
UBUNTU-CVE-2025-69720ncurses@6.5+20250216-2build1deb6.5+20250216-2ubuntu0.110/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-10536curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.510/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-11856curl@8.14.1-2ubuntu1.3debno fix listed10/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-5450glibc@2.42-0ubuntu3.1debno fix listed10/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8376perl@5.40.1-6build1deb5.40.1-6ubuntu0.110/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8925curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.410/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-9079curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.410/1002 Sept 20262fb3efa9eaa4
GHSA-45gg-vh54-h5m9

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

golang.org/x/crypto@v0.36.0golang0.52.010/1000.004 (30th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-9h84-qmv7-982p

Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.18.510/1000.003 (26th pct)2 Sept 20262fb3efa9eaa4

All 343 findings

Workloads and images

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

ContainerImageTagDigestRadar Score
Deployment candidate-argocd-applicationset-controller
applicationset-controllerquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Deployment candidate-argocd-notifications-controller
notifications-controllerquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Deployment candidate-argocd-repo-server
copyutilinitquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
repo-serverquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Deployment candidate-argocd-server
serverquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Deployment candidate-argocd-dex-server
copyutilinitquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
dex-serverghcr.io/dexidp/dexv2.45.18499afd690c41,104
Deployment candidate-argocd-redis
redisecr-public.aws.com/docker/library/redis8.2.3-alpineunmeasured: registry not in allow-list
StatefulSet candidate-argocd-application-controller
application-controllerquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Job candidate-argocd-redis-secret-init
secret-inithook: pre-install,pre-upgradequay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003

Unmeasured images (1)

  • ecr-public.aws.com/docker/library/redis:8.2.3-alpineregistry not in allow-list

Indexed versions

The latest version and the previous major, as selected nightly from the repository’s index.

VersionApp versionRadar ScoreBandMeasuredRender
10.6.4latestv3.5.22,461Medium2 / 3rendered 2 Sept 2026
9.7.1previous majorv3.4.43,107Medium2 / 3rendered 2 Sept 2026

helm v3.16.4 · syft 1.42.1 · rendered 2 Sept 2026 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.