Database/Container, Kubernetes & orchestration
Argo Workflows (Argo Server, WorkflowTemplate / ClusterWorkflowTemplate endpoints): The template endpoints serve
Impact
The template endpoints serve WorkflowTemplates and ClusterWorkflowTemplates to any caller sending an arbitrary Authorization header - literally 'Bearer nothing' works, because the handlers read from a shared informer instead of the caller's identity. Templates routinely embed Secret manifests, registry credentials and internal endpoints, so this hands an outsider the platform team's operational secrets and a full map of every tenant's pipeline.
Who can reach it
Anyone with network reach to the Argo Server API. Any garbage token satisfies the check.
What to do
Upgrade Argo Server to 3.7.11 or 4.0.2 and restart. Then rotate every credential that appears inside a WorkflowTemplate or ClusterWorkflowTemplate, since exposure leaves no distinguishing log entry.
References
Related entries
- Argo Workflows (Argo Server, webhook interceptor /api/v1/events/): The webhook interceptor buffers the entire requestCVE-2026-42294 · Argo Workflows (Argo Server, webhook interceptor /api/v1/events/)High
- Podman: Image env var with a key and no value causes Podman to pass the host's value of that variableCVE-2026-57231 · PodmanHigh
- Envoy: malformed upstream response trailers dispatch through a freed decoder and crash the proxyCVE-2026-73513 · Envoy (oghttp2 upstream HTTP/2 codec, ClientStreamImpl)High
- Envoy: duplicate Host headers escape request header limits and let a client OOM-kill the proxyCVE-2026-73550 · Envoy (HTTP/2 duplicate Host header handling, header-limit accounting)High
- Skipper: OPA body policies authorize oversized requests because truncated_body is derived from Content-LengthCVE-2026-86043 · Skipper HTTP router (opaAuthorizeRequestWithBody / OPA body truncation)High
- Envoy: Type-confusion in default certificate validationCVE-2022-21656 · EnvoyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.