argo-cd9.7.1
Helm chartA Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 17
- Low
- 402
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
419 findings over 2 of 3 images measured · scored 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of 9.7.1, one sample per day, last 90 days. Hover a point for its date and advisory data.
Score moves
A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves
Fewer than two samples so far.
Findings
showing 50 of 343
| Advisory | Package | Fixed in | Contribution | EPSS | Since | Digests |
|---|---|---|---|---|---|---|
| GHSA-5cgq-3rg8-m6cv golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 38/100 | 0.073 (94th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-2x32-jm95-2cpx Authentication Bypass in dex | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.27.0 | 25/100 | 0.017 (75th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-m9hp-7r99-94h5 Critical security issues in XML encoding in github.com/dexidp/dex | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.27.0 | 24/100 | 0.017 (75th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-p77j-4mvh-x3m3 gRPC-Go has an authorization bypass via missing leading slash in :path | google.golang.org/grpc@v1.72.1golang | 1.79.3 | 23/100 | 0.016 (73th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-vh7g-p26c-j2cw Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.35.0 | 21/100 | 0.012 (66th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-x527-x647-q7gg golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.005 (41th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.006 (47th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.006 (46th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-pc3f-x583-g7j2 SpdyStream: DOS on CRI | github.com/moby/spdystream@v0.5.0golang | 0.5.1 | 16/100 | 0.007 (49th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-rm3j-f69w-wqmq golang.org/x/crypto vulnerable to infinite loop on large channel writes | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 16/100 | 0.005 (42th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-r53h-jv2g-vpx6 Helm's Missing YAML Content Leads To Panic | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.14.2 | 16/100 | 0.009 (58th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 15/100 | 0.004 (35th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-jppx-rxg9-jmrx golang.org/x/crypto doesn't enforce invoking key constraints | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 15/100 | 0.004 (34th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-7hfp-qfw3-5jxh Helm Vulnerable to denial of service through string value parsing | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.9.4 | 14/100 | 0.010 (61th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-mh2q-q3fh-2475 OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) | go.opentelemetry.io/otel@v1.39.0golang | 1.41.0 | 14/100 | 0.007 (48th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-78h2-9frx-2jm8 Go JOSE Panics in JWE decryption | github.com/go-jose/go-jose/v4@v4.1.3golang | 4.1.4 | 14/100 | 0.007 (48th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-56hp-xqp3-w2jf Helm passes repository credentials to alternate domain | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.6.1 | 13/100 | 0.014 (70th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-557j-xg8c-q2mm Helm vulnerable to Code Injection through malicious chart.yaml content | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.4 | 13/100 | 0.004 (29th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-q4h4-gmj2-qvw2 golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 13/100 | 0.005 (39th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-w879-237q-wc7r golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 13/100 | 0.005 (38th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-8xwf-rjm4-xvhv oras-go has file store write outside workingDir via symlink traversal | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 12/100 | 0.005 (41th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-qw64-3x98-g7q2 go-billy has path traversal vulnerabilities | github.com/go-git/go-billy/v5@v5.6.2golang | 5.9.0 | 12/100 | 0.003 (23th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-jxpm-75mh-9fp7 oras-go blob upload vulnerable to credential forwarding via unvalidated Location header | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 12/100 | 0.004 (31th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-fxhp-mv3v-67qp `oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution | oras.land/oras-go/v2@v2.6.0golang | 2.6.2 | 12/100 | 0.004 (36th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-pjcq-xvwq-hhpj go-ntlmssp NTLM challenges can panic on malformed payloads | github.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358golang | 0.1.1 | 12/100 | 0.010 (61th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-v53g-5gjp-272r Helm dependency management path traversal | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.14.1 | 11/100 | 0.006 (45th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-hc8v-wwc9-vgxm go-git: Worktree operations may follow symlinks | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.2 | 11/100 | 0.004 (29th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4341 Memory exhaustion in query parameter parsing in net/url | stdlib@go1.24.11golang | 1.24.12 | 11/100 | 0.020 (79th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-479m-364c-43vc validateSignature Loop Variable Capture Signature Bypass in goxmldsig | github.com/russellhaering/goxmldsig@v1.5.0golang | 1.6.0 | 11/100 | 0.003 (22th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-5xqw-8hwv-wg92 Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.3 | 11/100 | 0.005 (38th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-53c4-hhmh-vw5q Helm vulnerable to denial of service through through repository index file | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 11/100 | 0.008 (54th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-67fx-wx78-jx33 Helm vulnerable to denial of service through schema file | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 11/100 | 0.008 (54th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-4hfp-h4cw-hj8p Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.3 | 11/100 | 0.004 (36th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-6rx9-889q-vv2r Helm vulnerable to denial of service through string value parsing | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 10/100 | 0.008 (52th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-xhf5-7wjv-pqxp containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull | github.com/containerd/containerd@v1.7.29golang | 1.7.33 | 10/100 | 0.002 (6th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-m3xc-h892-ggx6 go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion | github.com/go-git/go-billy/v5@v5.6.2golang | 5.9.0 | 10/100 | 0.004 (32th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-qgq7-7hm3-q39j go-git: Malicious reference names may modify files outside the reference storage | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.2 | 10/100 | 0.004 (34th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-hfvc-g4fc-pqhx opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking | go.opentelemetry.io/otel/sdk@v1.39.0golang | 1.43.0 | 10/100 | 0.003 (17th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-q9hv-hpm4-hj6x CIRCL has an incorrect calculation in secp384r1 CombinedMult | github.com/cloudflare/circl@v1.6.1golang | 1.6.3 | 10/100 | 0.004 (33th pct) | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-31789 | openssl@3.5.5-r0apk | 3.5.6-r0 | 10/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-63073 | openssl@3.5.5-r0apk | 3.5.8-r0 | 10/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2025-69720 | ncurses@6.5+20250216-2build1deb | 6.5+20250216-2ubuntu0.1 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-10536 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.5 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-11856 | curl@8.14.1-2ubuntu1.3deb | no fix listed | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-5450 | glibc@2.42-0ubuntu3.1deb | no fix listed | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8376 | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8925 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-9079 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-45gg-vh54-h5m9 golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 10/100 | 0.004 (30th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-9h84-qmv7-982p Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.18.5 | 10/100 | 0.003 (26th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
Workloads and images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
| Container | Image | Tag | Digest | Radar Score |
|---|---|---|---|---|
| Deployment candidate-argocd-applicationset-controller | ||||
| applicationset-controller | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Deployment candidate-argocd-notifications-controller | ||||
| notifications-controller | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Deployment candidate-argocd-repo-server | ||||
| copyutilinit | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| repo-server | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Deployment candidate-argocd-server | ||||
| server | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Deployment candidate-argocd-dex-server | ||||
| copyutilinit | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| dex-server | ghcr.io/dexidp/dex | v2.45.1 | 8499afd690c4 | 1,104 |
| Deployment candidate-argocd-redis | ||||
| redis | ecr-public.aws.com/docker/library/redis | 8.2.3-alpine | unmeasured: registry not in allow-list | — |
| StatefulSet candidate-argocd-application-controller | ||||
| application-controller | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Job candidate-argocd-redis-secret-init | ||||
| secret-inithook: pre-install,pre-upgrade | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
Unmeasured images (1)
ecr-public.aws.com/docker/library/redis:8.2.3-alpineregistry not in allow-list