Database/Container, Kubernetes & orchestration
Argo Workflows (Argo Server, ConfigMap-backed sync limit provider): The Sync Service's ConfigMap provider runs no
Impact
The Sync Service's ConfigMap provider runs no auth.CanI check on any CRUD path, so any authenticated caller - including one presenting a bogus bearer token - can create, edit or delete the ConfigMaps that hold workflow synchronization limits. Those limits are the concurrency gates on shared resources, so a tenant can raise their own ceiling or zero out someone else's and starve or stampede the GPU pool.
Who can reach it
Any client that can reach the Argo Server API and present any bearer token. Effectively unauthenticated in deployments that accept client-mode tokens.
What to do
Upgrade Argo Server to 4.0.5 and restart the deployment. Until patched, block the sync endpoints at the ingress and review the sync-limit ConfigMaps in each namespace for unexpected edits.
References
Related entries
- KubeVela: a ComponentDefinition can point terraform.path at a symlink and OOM-kill the cluster-wide controllerCVE-2026-55108 · KubeVela vela-core controller (Terraform remote configuration loader, GetTerraformConfigurationFromRemote)High
- CloudNativePG: managed-role passwords exposed via pg_stat_statements, enabling command execution in the DB podCVE-2026-55765 · CloudNativePG operator (managed-role password handling)High
- Kamaji: colliding tenant name normalization lets one tenant read or destroy another's control-plane stateCVE-2026-62246 · Kamaji hosted control plane manager (TenantControlPlane datastore schema/user derivation)High
- Docker / moby: Command execution via crafted remote git build path in `docker build`CVE-2019-13139 · Docker / mobyHigh
- Rancher: Sensitive data leaked into Rancher audit logsCVE-2023-22649 · RancherHigh
- runc: Insufficient checks when bind-mounting /dev/console allow writes to arbitrary host procfs pathsCVE-2025-52565 · runcHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.