quay.io/argoproj/argocd:v3.4.4
container imageDeployed by 0 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 8
- Low
- 278
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
286 findings on digest 2fb3efa9eaa4 · scanned 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of quay.io/argoproj/argocd:v3.4.4 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.
Findings
showing 50 of 286
Findings for digest 2fb3efa9eaa4 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.
| Advisory | Package | Fixed in | Contribution | EPSS | Since |
|---|---|---|---|---|---|
| GHSA-5cgq-3rg8-m6cv golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 38/100 | 0.073 (94th pct) | 2 Sept 2026 |
| GHSA-p77j-4mvh-x3m3 gRPC-Go has an authorization bypass via missing leading slash in :path | google.golang.org/grpc@v1.72.1golang | 1.79.3 | 23/100 | 0.016 (73th pct) | 2 Sept 2026 |
| GHSA-x527-x647-q7gg golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.005 (41th pct) | 2 Sept 2026 |
| GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GHSA-pc3f-x583-g7j2 SpdyStream: DOS on CRI | github.com/moby/spdystream@v0.5.0golang | 0.5.1 | 16/100 | 0.007 (49th pct) | 2 Sept 2026 |
| GHSA-rm3j-f69w-wqmq golang.org/x/crypto vulnerable to infinite loop on large channel writes | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 16/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GHSA-r53h-jv2g-vpx6 Helm's Missing YAML Content Leads To Panic | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.14.2 | 16/100 | 0.009 (58th pct) | 2 Sept 2026 |
| GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 15/100 | 0.004 (35th pct) | 2 Sept 2026 |
| GHSA-jppx-rxg9-jmrx golang.org/x/crypto doesn't enforce invoking key constraints | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 15/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GHSA-7hfp-qfw3-5jxh Helm Vulnerable to denial of service through string value parsing | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.9.4 | 14/100 | 0.010 (61th pct) | 2 Sept 2026 |
| GHSA-56hp-xqp3-w2jf Helm passes repository credentials to alternate domain | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.6.1 | 13/100 | 0.014 (70th pct) | 2 Sept 2026 |
| GHSA-557j-xg8c-q2mm Helm vulnerable to Code Injection through malicious chart.yaml content | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.4 | 13/100 | 0.004 (29th pct) | 2 Sept 2026 |
| GHSA-q4h4-gmj2-qvw2 golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 13/100 | 0.005 (39th pct) | 2 Sept 2026 |
| GHSA-w879-237q-wc7r golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 13/100 | 0.005 (38th pct) | 2 Sept 2026 |
| GHSA-8xwf-rjm4-xvhv oras-go has file store write outside workingDir via symlink traversal | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 12/100 | 0.005 (41th pct) | 2 Sept 2026 |
| GHSA-qw64-3x98-g7q2 go-billy has path traversal vulnerabilities | github.com/go-git/go-billy/v5@v5.6.2golang | 5.9.0 | 12/100 | 0.003 (23th pct) | 2 Sept 2026 |
| GHSA-jxpm-75mh-9fp7 oras-go blob upload vulnerable to credential forwarding via unvalidated Location header | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 12/100 | 0.004 (31th pct) | 2 Sept 2026 |
| GHSA-fxhp-mv3v-67qp `oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution | oras.land/oras-go/v2@v2.6.0golang | 2.6.2 | 12/100 | 0.004 (36th pct) | 2 Sept 2026 |
| GHSA-v53g-5gjp-272r Helm dependency management path traversal | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.14.1 | 11/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GHSA-hc8v-wwc9-vgxm go-git: Worktree operations may follow symlinks | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.2 | 11/100 | 0.004 (29th pct) | 2 Sept 2026 |
| GO-2026-4341 Memory exhaustion in query parameter parsing in net/url | stdlib@go1.24.11golang | 1.24.12 | 11/100 | 0.020 (79th pct) | 2 Sept 2026 |
| GHSA-5xqw-8hwv-wg92 Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.3 | 11/100 | 0.005 (38th pct) | 2 Sept 2026 |
| GHSA-53c4-hhmh-vw5q Helm vulnerable to denial of service through through repository index file | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 11/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GHSA-67fx-wx78-jx33 Helm vulnerable to denial of service through schema file | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 11/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GHSA-4hfp-h4cw-hj8p Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.3 | 11/100 | 0.004 (36th pct) | 2 Sept 2026 |
| GHSA-6rx9-889q-vv2r Helm vulnerable to denial of service through string value parsing | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 10/100 | 0.008 (52th pct) | 2 Sept 2026 |
| GHSA-xhf5-7wjv-pqxp containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull | github.com/containerd/containerd@v1.7.29golang | 1.7.33 | 10/100 | 0.002 (6th pct) | 2 Sept 2026 |
| GHSA-m3xc-h892-ggx6 go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion | github.com/go-git/go-billy/v5@v5.6.2golang | 5.9.0 | 10/100 | 0.004 (32th pct) | 2 Sept 2026 |
| GHSA-qgq7-7hm3-q39j go-git: Malicious reference names may modify files outside the reference storage | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.2 | 10/100 | 0.004 (34th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2025-69720 | ncurses@6.5+20250216-2build1deb | 6.5+20250216-2ubuntu0.1 | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-10536 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.5 | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-11856 | curl@8.14.1-2ubuntu1.3deb | no fix listed | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-5450 | glibc@2.42-0ubuntu3.1deb | no fix listed | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8376 | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8925 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-9079 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 10/100 | — | 2 Sept 2026 |
| GHSA-45gg-vh54-h5m9 golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 10/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GHSA-9h84-qmv7-982p Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.18.5 | 10/100 | 0.003 (26th pct) | 2 Sept 2026 |
| GHSA-f9f8-9pmf-xv68 Helm May Panic Due To Incorrect YAML Content | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.18.5 | 10/100 | 0.003 (26th pct) | 2 Sept 2026 |
| GHSA-5cv4-jp36-h3mw Go Net HTML parser is vulnerable to denial of service | golang.org/x/net@v0.47.0golang | 0.55.0 | 10/100 | 0.003 (25th pct) | 2 Sept 2026 |
| GHSA-jpcc-p29g-p8mq containerd image-triggered runtime DoS via unbounded group parsing | github.com/containerd/containerd@v1.7.29golang | 1.7.33 | 10/100 | 0.003 (18th pct) | 2 Sept 2026 |
| GHSA-j5w8-q4qc-rx2x golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption | golang.org/x/crypto@v0.36.0golang | 0.45.0 | 9/100 | 0.006 (44th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-4739 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 9/100 | — | 2 Sept 2026 |
| GHSA-fqw6-gf59-qr4w containerd user ID handling bypass allows runAsNonRoot evasion | github.com/containerd/containerd@v1.7.29golang | 1.7.32 | 9/100 | 0.002 (6th pct) | 2 Sept 2026 |
| GHSA-qpw4-5x99-6vjp golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 9/100 | 0.003 (20th pct) | 2 Sept 2026 |
| GHSA-f6x5-jh6r-wrfv golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read | golang.org/x/crypto@v0.36.0golang | 0.45.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-12087 | perl@5.40.1-6build1deb | no fix listed | 9/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-42496 | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 9/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8924 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 9/100 | — | 2 Sept 2026 |
Tags and digests
Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.
| Tag | Digest | Platform | First seen | Last seen | Radar Score |
|---|---|---|---|---|---|
| v3.4.4current | 2fb3efa9eaa4 | linux/amd64 | 2 Sept 2026 | 2 Sept 2026 | 2,003 |
Used by
Charts whose default render references this repository, with the workload that carries it.
No indexed chart deploys this repository in its latest version.
Also in older indexed versions (1)
Not counted above: the chart’s latest version no longer references it, or the chart is no longer in the top N.
- argo-cdargo
- Deployment/candidate-argocd-applicationset-controller/applicationset-controller:v3.4.4
- Deployment/candidate-argocd-notifications-controller/notifications-controller:v3.4.4
- Deployment/candidate-argocd-repo-server/copyutilinit:v3.4.4
- Deployment/candidate-argocd-repo-server/repo-server:v3.4.4
- Deployment/candidate-argocd-server/server:v3.4.4
- Deployment/candidate-argocd-dex-server/copyutilinit:v3.4.4
- StatefulSet/candidate-argocd-application-controller/application-controller:v3.4.4
- Job/candidate-argocd-redis-secret-init/secret-inithook: pre-install,pre-upgrade:v3.4.4