quay.io/argoproj/argocd:v3.4.4

container image

Deployed by 0 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.

Radar Score

2,003
worst finding Medium
Critical
0
High
0
Medium
8
Low
278
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

286 findings on digest 2fb3efa9eaa4 · scanned 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of quay.io/argoproj/argocd:v3.4.4 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.

2 Sept 2026 · Radar Score 2,003 · OSV as of 2 Sept 2026 · digest 2fb3efa9eaa4
history since 2 Sept 2026

Findings

showing 50 of 286

Findings for digest 2fb3efa9eaa4 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.

AdvisoryPackageFixed inContributionEPSSSince
GHSA-5cgq-3rg8-m6cv

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

golang.org/x/crypto@v0.36.0golang0.52.038/1000.073 (94th pct)2 Sept 2026
GHSA-p77j-4mvh-x3m3

gRPC-Go has an authorization bypass via missing leading slash in :path

google.golang.org/grpc@v1.72.1golang1.79.323/1000.016 (73th pct)2 Sept 2026
GHSA-x527-x647-q7gg

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

golang.org/x/crypto@v0.36.0golang0.52.017/1000.005 (41th pct)2 Sept 2026
GHSA-vgwf-h737-ff37

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto@v0.36.0golang0.52.017/1000.006 (47th pct)2 Sept 2026
GHSA-f5wc-c3c7-36mc

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto@v0.36.0golang0.52.017/1000.006 (46th pct)2 Sept 2026
GHSA-pc3f-x583-g7j2

SpdyStream: DOS on CRI

github.com/moby/spdystream@v0.5.0golang0.5.116/1000.007 (49th pct)2 Sept 2026
GHSA-rm3j-f69w-wqmq

golang.org/x/crypto vulnerable to infinite loop on large channel writes

golang.org/x/crypto@v0.36.0golang0.52.016/1000.005 (42th pct)2 Sept 2026
GHSA-r53h-jv2g-vpx6

Helm's Missing YAML Content Leads To Panic

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.14.216/1000.009 (58th pct)2 Sept 2026
GHSA-89gr-r52h-f8rx

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

golang.org/x/crypto@v0.36.0golang0.52.015/1000.004 (35th pct)2 Sept 2026
GHSA-jppx-rxg9-jmrx

golang.org/x/crypto doesn't enforce invoking key constraints

golang.org/x/crypto@v0.36.0golang0.52.015/1000.004 (34th pct)2 Sept 2026
GHSA-7hfp-qfw3-5jxh

Helm Vulnerable to denial of service through string value parsing

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.9.414/1000.010 (61th pct)2 Sept 2026
GHSA-56hp-xqp3-w2jf

Helm passes repository credentials to alternate domain

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.6.113/1000.014 (70th pct)2 Sept 2026
GHSA-557j-xg8c-q2mm

Helm vulnerable to Code Injection through malicious chart.yaml content

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.413/1000.004 (29th pct)2 Sept 2026
GHSA-q4h4-gmj2-qvw2

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

golang.org/x/crypto@v0.36.0golang0.52.013/1000.005 (39th pct)2 Sept 2026
GHSA-w879-237q-wc7r

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

golang.org/x/crypto@v0.36.0golang0.52.013/1000.005 (38th pct)2 Sept 2026
GHSA-8xwf-rjm4-xvhv

oras-go has file store write outside workingDir via symlink traversal

oras.land/oras-go/v2@v2.6.0golang2.6.112/1000.005 (41th pct)2 Sept 2026
GHSA-qw64-3x98-g7q2

go-billy has path traversal vulnerabilities

github.com/go-git/go-billy/v5@v5.6.2golang5.9.012/1000.003 (23th pct)2 Sept 2026
GHSA-jxpm-75mh-9fp7

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

oras.land/oras-go/v2@v2.6.0golang2.6.112/1000.004 (31th pct)2 Sept 2026
GHSA-fxhp-mv3v-67qp

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

oras.land/oras-go/v2@v2.6.0golang2.6.212/1000.004 (36th pct)2 Sept 2026
GHSA-v53g-5gjp-272r

Helm dependency management path traversal

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.14.111/1000.006 (45th pct)2 Sept 2026
GHSA-hc8v-wwc9-vgxm

go-git: Worktree operations may follow symlinks

github.com/go-git/go-git/v5@v5.14.0golang5.19.211/1000.004 (29th pct)2 Sept 2026
GO-2026-4341

Memory exhaustion in query parameter parsing in net/url

stdlib@go1.24.11golang1.24.1211/1000.020 (79th pct)2 Sept 2026
GHSA-5xqw-8hwv-wg92

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.311/1000.005 (38th pct)2 Sept 2026
GHSA-53c4-hhmh-vw5q

Helm vulnerable to denial of service through through repository index file

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.311/1000.008 (54th pct)2 Sept 2026
GHSA-67fx-wx78-jx33

Helm vulnerable to denial of service through schema file

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.311/1000.008 (54th pct)2 Sept 2026
GHSA-4hfp-h4cw-hj8p

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.311/1000.004 (36th pct)2 Sept 2026
GHSA-6rx9-889q-vv2r

Helm vulnerable to denial of service through string value parsing

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.310/1000.008 (52th pct)2 Sept 2026
GHSA-xhf5-7wjv-pqxp

containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

github.com/containerd/containerd@v1.7.29golang1.7.3310/1000.002 (6th pct)2 Sept 2026
GHSA-m3xc-h892-ggx6

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

github.com/go-git/go-billy/v5@v5.6.2golang5.9.010/1000.004 (32th pct)2 Sept 2026
GHSA-qgq7-7hm3-q39j

go-git: Malicious reference names may modify files outside the reference storage

github.com/go-git/go-git/v5@v5.14.0golang5.19.210/1000.004 (34th pct)2 Sept 2026
UBUNTU-CVE-2025-69720ncurses@6.5+20250216-2build1deb6.5+20250216-2ubuntu0.110/1002 Sept 2026
UBUNTU-CVE-2026-10536curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.510/1002 Sept 2026
UBUNTU-CVE-2026-11856curl@8.14.1-2ubuntu1.3debno fix listed10/1002 Sept 2026
UBUNTU-CVE-2026-5450glibc@2.42-0ubuntu3.1debno fix listed10/1002 Sept 2026
UBUNTU-CVE-2026-8376perl@5.40.1-6build1deb5.40.1-6ubuntu0.110/1002 Sept 2026
UBUNTU-CVE-2026-8925curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.410/1002 Sept 2026
UBUNTU-CVE-2026-9079curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.410/1002 Sept 2026
GHSA-45gg-vh54-h5m9

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

golang.org/x/crypto@v0.36.0golang0.52.010/1000.004 (30th pct)2 Sept 2026
GHSA-9h84-qmv7-982p

Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.18.510/1000.003 (26th pct)2 Sept 2026
GHSA-f9f8-9pmf-xv68

Helm May Panic Due To Incorrect YAML Content

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.18.510/1000.003 (26th pct)2 Sept 2026
GHSA-5cv4-jp36-h3mw

Go Net HTML parser is vulnerable to denial of service

golang.org/x/net@v0.47.0golang0.55.010/1000.003 (25th pct)2 Sept 2026
GHSA-jpcc-p29g-p8mq

containerd image-triggered runtime DoS via unbounded group parsing

github.com/containerd/containerd@v1.7.29golang1.7.3310/1000.003 (18th pct)2 Sept 2026
GHSA-j5w8-q4qc-rx2x

golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

golang.org/x/crypto@v0.36.0golang0.45.09/1000.006 (44th pct)2 Sept 2026
UBUNTU-CVE-2026-4739expat@2.7.1-2ubuntu0.2debno fix listed9/1002 Sept 2026
GHSA-fqw6-gf59-qr4w

containerd user ID handling bypass allows runAsNonRoot evasion

github.com/containerd/containerd@v1.7.29golang1.7.329/1000.002 (6th pct)2 Sept 2026
GHSA-qpw4-5x99-6vjp

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

golang.org/x/crypto@v0.36.0golang0.52.09/1000.003 (20th pct)2 Sept 2026
GHSA-f6x5-jh6r-wrfv

golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read

golang.org/x/crypto@v0.36.0golang0.45.09/1000.005 (41th pct)2 Sept 2026
UBUNTU-CVE-2026-12087perl@5.40.1-6build1debno fix listed9/1002 Sept 2026
UBUNTU-CVE-2026-42496perl@5.40.1-6build1deb5.40.1-6ubuntu0.19/1002 Sept 2026
UBUNTU-CVE-2026-8924curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.49/1002 Sept 2026

All 286 findings

Tags and digests

Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.

TagDigestPlatformFirst seenLast seenRadar Score
v3.4.4current2fb3efa9eaa4linux/amd642 Sept 20262 Sept 20262,003

Used by

Charts whose default render references this repository, with the workload that carries it.

No indexed chart deploys this repository in its latest version.

Also in older indexed versions (1)

Not counted above: the chart’s latest version no longer references it, or the chart is no longer in the top N.

    • Deployment/candidate-argocd-applicationset-controller/applicationset-controller:v3.4.4
    • Deployment/candidate-argocd-notifications-controller/notifications-controller:v3.4.4
    • Deployment/candidate-argocd-repo-server/copyutilinit:v3.4.4
    • Deployment/candidate-argocd-repo-server/repo-server:v3.4.4
    • Deployment/candidate-argocd-server/server:v3.4.4
    • Deployment/candidate-argocd-dex-server/copyutilinit:v3.4.4
    • StatefulSet/candidate-argocd-application-controller/application-controller:v3.4.4
    • Job/candidate-argocd-redis-secret-init/secret-inithook: pre-install,pre-upgrade:v3.4.4

syft 1.42.1 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.