CVE-2025-59537

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. With the default configuration, no webhook.gogs.secret set, Argo CD’s /api/webhook endpoint will crash the entire argocd-server process when it receives a Gogs push event whose JSON field commits[].repo is not set or is null. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
cpe:2.3:a:argoproj:argo_cd:3.2.0:rc1:*:*:*:*:*:*

History

07 Oct 2025, 14:34

Type Values Removed Values Added
References () https://github.com/argoproj/argo-cd/commit/761fc27068d2d4cd24e1f784eb2a9033b5ee7f43 - () https://github.com/argoproj/argo-cd/commit/761fc27068d2d4cd24e1f784eb2a9033b5ee7f43 - Patch
References () https://github.com/argoproj/argo-cd/security/advisories/GHSA-wp4p-9pxh-cgx2 - () https://github.com/argoproj/argo-cd/security/advisories/GHSA-wp4p-9pxh-cgx2 - Exploit, Vendor Advisory, Mitigation
CPE cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
cpe:2.3:a:argoproj:argo_cd:3.2.0:rc1:*:*:*:*:*:*
First Time Argoproj
Argoproj argo Cd

02 Oct 2025, 16:15

Type Values Removed Values Added
References () https://github.com/argoproj/argo-cd/security/advisories/GHSA-wp4p-9pxh-cgx2 - () https://github.com/argoproj/argo-cd/security/advisories/GHSA-wp4p-9pxh-cgx2 -

01 Oct 2025, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-01 21:16

Updated : 2025-10-07 14:34


NVD link : CVE-2025-59537

Mitre link : CVE-2025-59537

CVE.ORG link : CVE-2025-59537


JSON object : View

Products Affected

argoproj

  • argo_cd
CWE
CWE-20

Improper Input Validation

CWE-476

NULL Pointer Dereference