PatchSiren cyber security CVE debrief
CVE-2026-42183 argoproj CVE debrief
CVE-2026-42183 affects Argo Workflows 4.0.0 through before 4.0.5. In the affected SSO/RBAC configuration, a nil pointer dereference in gatekeeper authorization handling can panic the server and interrupt service for certain authenticated users. The issue is patched in Argo Workflows 4.0.5.
- Vendor
- argoproj
- Product
- argo-workflows
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-09
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-09
- Advisory updated
- 2026-07-24
Who should care
Operators and administrators running Argo Workflows 4.0.0 through 4.0.4, especially if SSO_DELEGATE_RBAC_TO_NAMESPACE=true and namespace-level RBAC is in use.
Technical summary
The vulnerability is a nil pointer dereference in server/auth/gatekeeper.go rbacAuthorization(). According to the supplied advisory description, the panic can occur for SSO users whose claims match a namespace-level RBAC rule but do not match an SSO-namespace rule, when SSO_DELEGATE_RBAC_TO_NAMESPACE=true. The weakness is mapped to CWE-476. The result is a denial of service via server panic rather than code execution.
Defensive priority
Low overall severity, but patch promptly if you use the affected SSO/RBAC delegation path because the failure mode is a service-impacting panic.
Recommended defensive actions
- Upgrade Argo Workflows to version 4.0.5 or later.
- Check whether SSO_DELEGATE_RBAC_TO_NAMESPACE=true is enabled in your deployment.
- Review namespace-level and SSO-namespace RBAC mappings for any environments using delegated RBAC.
- Monitor workflow controller/server logs for panic traces related to gatekeeper authorization.
- Validate the upgrade in staging before rolling it into production.
Evidence notes
The supplied NVD record lists CVE-2026-42183 as received on 2026-05-09 and references a GitHub security advisory, a fix commit, and the Argo Workflows v4.0.5 release. NVD also supplies a CVSS v4.0 vector and a CWE-476 classification. The public description states the affected range is 4.0.0 to before 4.0.5 and that the issue is fixed in 4.0.5.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42183 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42183
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42183 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42183
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-workflows/commit/c4cc17d0c034fa9a9cc01ef1af6c8016c93071d4
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-workflows/releases/tag/v4.0.5
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-workflows/security/advisories/GHSA-p4gq-3vxj-f4jq
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.