PatchSiren cyber security CVE debrief
CVE-2026-42295 argoproj CVE debrief
CVE-2026-42295 affects Argo Workflows and can expose artifact repository credentials in plaintext through workflow executor logs. In versions 4.0.0 through before 4.0.5, anyone with read access to workflow pod logs could extract secrets such as S3 access keys, GCS service account keys, Azure account keys, or Git passwords. The issue is fixed in Argo Workflows 4.0.5.
- Vendor
- argoproj
- Product
- argo-workflows
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-09
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-09
- Advisory updated
- 2026-07-24
Who should care
Argo Workflows operators, Kubernetes platform teams, security and incident response teams, and anyone who can read workflow pod logs or manages artifact repository credentials.
Technical summary
The vulnerability is a sensitive-data exposure issue in the workflow executor's artifact handling path. During artifact operations, credentials for artifact repositories are written to logs in plaintext, creating a path for credential theft through log access. NVD lists the issue at CVSS 4.0 8.5 (HIGH) with a vector indicating network-based attack conditions, no user interaction, and high confidentiality/integrity impact; GitHub advisory metadata maps the weakness to CWE-522.
Defensive priority
High
Recommended defensive actions
- Upgrade Argo Workflows to version 4.0.5 or later.
- Restrict access to workflow pod logs to the minimum required set of users and services.
- Rotate any artifact repository credentials that may have been exposed in logs.
- Audit existing workflow logs for plaintext credential exposure and remove or protect any sensitive records according to retention policy.
- Review artifact repository credential handling and logging controls to ensure secrets are never written to logs.
Evidence notes
The supplied CVE description states that Argo Workflows versions 4.0.0 to before 4.0.5 log artifact repository credentials in plaintext during artifact operations and that the issue is patched in 4.0.5. The NVD record supplies CVSS 4.0 vector AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N and cites GitHub advisory metadata identifying CWE-522. The official references supplied are the Argo Workflows v4.0.5 release and GHSA-7vf8-2cr6-54mf advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42295 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42295
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42295 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42295
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-workflows/releases/tag/v4.0.5
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-workflows/security/advisories/GHSA-7vf8-2cr6-54mf
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.