StackRadar

CVE-2024-32476

Medium

Advisory

Published 26 Apr 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 2
affected packages

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
github.com/argoproj/argo-cd/v2golangv2.4.7, v2.4.11, v2.7.2, v2.7.8+3 more2.8.17, 2.9.137
github.com/argoproj/argo-cdgolangv1.5.8no fix listed1
OSV records
GHSA-9m6p-x4h2-6frqGO-2024-2792
Also known as
BIT-argo-cd-2024-32476

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/argoproj/argo-cd/v2@v2.8.16
2.8.17

Open the chart page →

3,793
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/argoproj/argo-cd/v2@v2.8.6
2.8.17

Open the chart page →

10,315
devtron-in-clustercddevtron0.10.21 of 2See more

devtron-in-clustercd devtron 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.8.17

Open the chart page →

5,039
devtron-in-clustercddevtron-labs0.10.21 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.8.17

Open the chart page →

5,039
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/argoproj/argo-cd/v2@v2.4.11
2.8.17

Open the chart page →

13,450
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/argoproj/argo-cd/v2@v2.7.8
2.8.17

Open the chart page →

2,607
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.8.17

Open the chart page →

5,039
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/argoproj/argo-cd/v2@v2.9.3
2.9.13

Open the chart page →

2,314
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
github.com/argoproj/argo-cd@v1.5.8
no fix listed

Open the chart page →

6,671
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-32476.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
github.com/argoproj/argo-cd/v2@v2.4.7
2.8.17

Open the chart page →

1,985

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.8.17
3
sikalabs/slu:v0.72.07bd267f30247
github.com/argoproj/argo-cd/v2@v2.9.3
2.9.13
1
stakater/workshop-operator:v0.0.3897bf456cc97c
github.com/argoproj/argo-cd@v1.5.8
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/argoproj/argo-cd/v2@v2.4.11
2.8.17
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/argoproj/argo-cd/v2@v2.8.6
2.8.17
1
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
github.com/argoproj/argo-cd/v2@v2.4.7
2.8.17
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/argoproj/argo-cd/v2@v2.7.8
2.8.17
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/argoproj/argo-cd/v2@v2.8.16
2.8.17
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.