StackRadar

CVE-2026-42297

Unscored

Advisory

Published 25 Jun 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
None
affected package

Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
github.com/argoproj/argo-workflows/v3golangv0.0.0-20260108083749-26c24fd5909b, v3.2.3, v3.3.8, v3.4.7+5 moreno fix listed15
OSV records
GO-2026-5751
Also known as
BIT-argo-workflows-2026-42297, GHSA-xchc-cqwg-g76q

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
argo-eventsargoOfficialVerified publisher2.4.271 of 1See more

argo-events argo 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/argoproj/argo-workflows/v3@v3.7.9
no fix listed

Open the chart page →

969
kubeflowkubeflow1.6.24 of 45See more

kubeflow kubeflow 1.6.2

4 of the 45 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
github.com/argoproj/argo-workflows/v3@v3.3.8
no fix listed
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
github.com/argoproj/argo-workflows/v3@v3.3.8
no fix listed
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
github.com/argoproj/argo-workflows/v3@v3.3.8
no fix listed
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
github.com/argoproj/argo-workflows/v3@v3.3.8
no fix listed

Open the chart page →

96,941
clechaosnative0.2.71 of 6See more

cle chaosnative 0.2.7

1 of the 6 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
chaosnative/cle-server:2.7.0e7bcff4a20c0
github.com/argoproj/argo-workflows/v3@v3.2.3
no fix listed

Open the chart page →

16,389
argo-eventscluster-deploy0.1.01 of 1See more

argo-events cluster-deploy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
github.com/argoproj/argo-workflows/v3@v0.0.0-20260108083749-26c24fd5909b
no fix listed

Open the chart page →

1,035
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
github.com/argoproj/argo-workflows/v3@v3.6.12
no fix listed

Open the chart page →

58,897
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/argoproj/argo-workflows/v3@v3.7.11
no fix listed

Open the chart page →

68,240
devtron-in-clustercddevtron0.10.21 of 2See more

devtron-in-clustercd devtron 0.10.2

1 of the 2 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-workflows/v3@v3.4.7
no fix listed

Open the chart page →

5,039
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/argoproj/argo-workflows/v3@v3.7.11
no fix listed

Open the chart page →

68,240
devtron-in-clustercddevtron-labs0.10.21 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

1 of the 2 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-workflows/v3@v3.4.7
no fix listed

Open the chart page →

5,039
kubeflowkromanow94-kubeflow0.5.14 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

4 of the 30 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
github.com/argoproj/argo-workflows/v3@v3.4.17
no fix listed
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
github.com/argoproj/argo-workflows/v3@v3.4.17
no fix listed
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
github.com/argoproj/argo-workflows/v3@v3.4.17
no fix listed
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
github.com/argoproj/argo-workflows/v3@v3.4.17
no fix listed

Open the chart page →

70,530
pipekit-agentpipekit-helmOfficialVerified publisher7.6.01 of 1See more

pipekit-agent pipekit-helm 7.6.0

1 of the 1 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
pipekit13/agent:v7.6.0c3f01b5ac3b2
github.com/argoproj/argo-workflows/v3@v3.7.18
no fix listed

Open the chart page →

103
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/argoproj/argo-workflows/v3@v3.7.11
no fix listed

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-workflows/v3@v3.4.7
no fix listed

Open the chart page →

5,039
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-42297.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/argoproj/argo-workflows/v3@v3.7.9
no fix listed

Open the chart page →

969

Container images carrying it

15 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/argoproj/argo-workflows/v3@v3.7.11
no fix listed
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-workflows/v3@v3.4.7
no fix listed
3
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/argoproj/argo-workflows/v3@v3.7.9
no fix listed
2
chaosnative/cle-server:2.7.0e7bcff4a20c0
github.com/argoproj/argo-workflows/v3@v3.2.3
no fix listed
1
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
github.com/argoproj/argo-workflows/v3@v3.6.12
no fix listed
1
pipekit13/agent:v7.6.0c3f01b5ac3b2
github.com/argoproj/argo-workflows/v3@v3.7.18
no fix listed
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
github.com/argoproj/argo-workflows/v3@v3.4.17
no fix listed
1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
github.com/argoproj/argo-workflows/v3@v3.3.8
no fix listed
1
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
github.com/argoproj/argo-workflows/v3@v3.4.17
no fix listed
1
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
github.com/argoproj/argo-workflows/v3@v3.3.8
no fix listed
1
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
github.com/argoproj/argo-workflows/v3@v3.3.8
no fix listed
1
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
github.com/argoproj/argo-workflows/v3@v3.4.17
no fix listed
1
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
github.com/argoproj/argo-workflows/v3@v3.3.8
no fix listed
1
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
github.com/argoproj/argo-workflows/v3@v3.4.17
no fix listed
1
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
github.com/argoproj/argo-workflows/v3@v0.0.0-20260108083749-26c24fd5909b
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.