StackRadar

CVE-2026-40886

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
4
deployed by those charts
Fix available
1 of 1
affected package

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 4 images.

Affected packageAffected versionsFixed inImages
github.com/argoproj/argo-workflows/v3golangv3.6.12, v3.7.9, v3.7.11, v3.7.183.7.144
OSV records
GHSA-5jv8-h7qh-rf5pGO-2026-5148
Also known as
BIT-argo-workflows-2026-40886

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
argo-eventsargoOfficialVerified publisher2.4.271 of 1See more

argo-events argo 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-40886.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/argoproj/argo-workflows/v3@v3.7.9
3.7.14

Open the chart page →

969
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-40886.

Container imageDigestPackageFixed in
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
github.com/argoproj/argo-workflows/v3@v3.6.12
no fix listed

Open the chart page →

58,897
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-40886.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/argoproj/argo-workflows/v3@v3.7.11
3.7.14

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-40886.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/argoproj/argo-workflows/v3@v3.7.11
3.7.14

Open the chart page →

68,240
pipekit-agentpipekit-helmOfficialVerified publisher7.6.01 of 1See more

pipekit-agent pipekit-helm 7.6.0

1 of the 1 container images this version deploys carry CVE-2026-40886.

Container imageDigestPackageFixed in
pipekit13/agent:v7.6.0c3f01b5ac3b2
github.com/argoproj/argo-workflows/v3@v3.7.18
no fix listed

Open the chart page →

103
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-40886.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/argoproj/argo-workflows/v3@v3.7.11
3.7.14

Open the chart page →

68,240
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-40886.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/argoproj/argo-workflows/v3@v3.7.9
3.7.14

Open the chart page →

969

Container images carrying it

4 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/argoproj/argo-workflows/v3@v3.7.11
3.7.14
3
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/argoproj/argo-workflows/v3@v3.7.9
3.7.14
2
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
github.com/argoproj/argo-workflows/v3@v3.6.12
no fix listed
1
pipekit13/agent:v7.6.0c3f01b5ac3b2
github.com/argoproj/argo-workflows/v3@v3.7.18
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.