StackRadar

argo-cd 10.9.4 Helm chart

argoOfficialVerified publisher

Scored 30 Sept 2026

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

Version 10.9.4 todayapp version v3.5.3 850Artifact Hub

argo-cd 10.9.4 deploys 3 container images: quay.io/argoproj/argocd, ghcr.io/dexidp/dex and ecr-public.aws.com/docker/library/redis. Across them, 356 findings — 0 critical, 0 high. The highest contribution is ALPINE-CVE-2026-45447 in openssl 3.5.5-r0, fixed in 3.5.7-r0. Chart.yaml declares kubeVersion >=1.25.0-0; rendered for Kubernetes 1.25.0.

Radar Score

3,1550049307

356 findings over 3 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
quay.io/argoproj/argocd×8v3.5.300121961,562
ghcr.io/dexidp/dexv2.45.100311051,410
ecr-public.aws.com/docker/library/redis8.6.4-alpine0066183

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

34 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumALPINE-CVE-2026-45447openssl@3.5.5-r03.5.7-r0
MediumGHSA-2x32-jm95-2cpxgithub.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b422.27.0
MediumGHSA-m9hp-7r99-94h5github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b422.27.0
MediumGHSA-p77j-4mvh-x3m3google.golang.org/grpc@v1.79.11.79.3
MediumALPINE-CVE-2026-63073openssl@3.5.7-r03.5.8-r0
MediumALPINE-CVE-2026-28388openssl@3.5.5-r03.5.6-r0
MediumALPINE-CVE-2026-28389openssl@3.5.5-r03.5.6-r0
MediumGHSA-vh7g-p26c-j2cwgithub.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b422.35.0
MediumALPINE-CVE-2026-34182openssl@3.5.5-r03.5.7-r0
MediumALPINE-CVE-2026-63076openssl@3.5.7-r03.5.8-r0
MediumALPINE-CVE-2026-18798openssl@3.5.7-r03.5.8-r0
MediumGHSA-x527-x647-q7gggolang.org/x/crypto@v0.36.00.52.0
MediumALPINE-CVE-2026-34180openssl@3.5.5-r03.5.7-r0
MediumALPINE-CVE-2026-54874openssl@3.5.7-r03.5.8-r0
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.36.00.52.0
MediumALPINE-CVE-2026-28387openssl@3.5.5-r03.5.6-r0
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.36.00.52.0
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.36.00.52.0
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.36.00.52.0
MediumALPINE-CVE-2026-34183openssl@3.5.5-r03.5.7-r0
MediumUBUNTU-CVE-2026-18924curl@8.18.0-1ubuntu2.58.18.0-1ubuntu2.7
MediumALPINE-CVE-2026-31790openssl@3.5.5-r03.5.6-r0
MediumALPINE-CVE-2026-14457openssl@3.5.7-r03.5.8-r0
MediumGHSA-m37j-52j7-pjw7oras.land/oras-go/v2@v2.6.12.6.2
MediumALPINE-CVE-2026-63072openssl@3.5.7-r03.5.8-r0
MediumGHSA-2v4p-qf9q-27wjgoogle.golang.org/grpc@v1.81.11.82.2
MediumALPINE-CVE-2026-9076openssl@3.5.5-r03.5.7-r0
MediumGHSA-vp52-pcj8-j9qcgoogle.golang.org/grpc@v1.81.11.83.1
MediumALPINE-CVE-2026-7383openssl@3.5.5-r03.5.7-r0
MediumGHSA-mh2q-q3fh-2475go.opentelemetry.io/otel@v1.39.01.41.0
MediumGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.36.00.52.0
MediumGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.36.00.52.0
MediumUBUNTU-CVE-2024-52005git@1:2.53.0-1ubuntu1no fix listed
MediumALPINE-CVE-2026-28390openssl@3.5.5-r03.5.6-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
10.9.4latesttodayv3.5.300493073,155
10.9.213 days agov3.5.300493073,155
10.9.116 days agov3.5.300493073,155
10.9.019 days agov3.5.200463173,278
10.8.421 days agov3.5.200463173,278
10.8.223 days agov3.5.200403113,095
10.8.124 days agov3.5.200403113,095
10.8.025 days agov3.5.200403113,095

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/argo/argo-cd.svg)](https://charts.stackradar.io/charts/argo/argo-cd)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 30 Sept 2026 · scanned 30 Sept 2026 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.