Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.44% | — | Argo WorkflowsAI | 19/9/2026 | 22/9/2026 | Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field… | |
| Pendiente de análisis | Alta (7.6) | 0.51% | — | Data Science PipelinesAIArgoproj Argo WorkflowsAI | 10/8/2026 | 8/9/2026 | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker.… | |
| Pendiente de análisis | Crítica (9.3) | 0.73% | — | Wazuh WorkflowsAI | 1/8/2026 | 9/9/2026 | Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps,… | |
| Analizada | Alta (8.9) | 0.55% | — | Argoproj Argo Workflows | 16/7/2026 | 30/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUserOverrides and SanitizeUserWorkflowSpec walk only the top-level fields of… | |
| Analizada | Crítica (9.8) | 2.1% | — | Localgovdrupal Localgov Workflows | 10/7/2026 | 6/8/2026 | Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. | |
| Aplazada | Baja (2.2) | 0.09% | — | Github WorkflowsAI | 17/6/2026 | 22/6/2026 | The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location. | |
| Modificada | Alta (8.5) | 0.53% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provider (server/sync/sync_cm.go) performs zero authorization checks on all CRUD operations (create, read, update, delete).… | |
| Modificada | Alta (8.1) | 0.49% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add… | |
| Analizada | Alta (8.5) | 0.40% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the workflow executor logs all artifact repository credentials (S3 access keys, secret keys, GCS service account keys, Azure account keys, Git passwords, etc.) in… | |
| Modificada | Alta (8.2) | 0.74% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads the entire request body into memory before authenticating the request or verifying its signature. This occurs on the /api/v1/events/… | |
| Analizada | Baja (2.3) | 0.57% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/gatekeeper.go rbacAuthorization() causes a panic (denial of service) for SSO users whose claims match a namespace-level… | |
| Modificada | Alta (7.7) | 0.59% | — | Argoproj Argo Workflows | 23/4/2026 | 15/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pod-gc-strategy… | |
| Modificada | Alta (8.9) | 0.65% | — | Argoproj Argo Workflows | 11/3/2026 | 15/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in their Workflow… | |
| Modificada | Alta (7.5) | 0.78% | — | Argoproj Argo Workflows | 11/3/2026 | 15/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak… | |
| Modificada | Alta (7.3) | 0.40% | — | Argoproj Argo Workflows | 21/1/2026 | 15/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbitrary JavaScript in another user’s browser under the Argo Server origin, enabling… | |
| Analizada | Alta (7.5) | 0.68% | — | Argoproj Argo Workflows | 9/12/2025 | 17/6/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versions 3.7.0 through 3.7.4, contain unsafe untar code that handles symbolic links in archives. Concretely, the computation of a link's target and the subsequent check are… | |
| Analizada | Alta (8.5) | 0.47% | — | Argoproj Argo Workflows | 14/10/2025 | 17/6/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in… | |
| Analizada | Alta (8.8) | 0.59% | — | Argoproj Argo Workflows | 14/10/2025 | 17/6/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 contain a Zip Slip path traversal vulnerability in artifact extraction. During artifact extraction the unpack/untar logic… | |
| Analizada | Media (6.3) | 0.66% | — | Argoproj Argo Workflows | 2/12/2024 | 17/6/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When using `--auth-mode=client`, Archived Workflows can be retrieved with a fake or spoofed token via the GET Workflow endpoint: `/api/v1/workflows/{namespace}/{name}` or when using `--auth-mode=sso`, all… | |
| Aplazada | Alta (8.2) | 0.21% | — | Argo Workflows ChartAI | 21/11/2024 | 17/6/2026 | Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workflow-role has excessive privileges, the worst being create pods/exec, which will allow kubectl exec into any Pod in the same namespace, i.e. arbitrary code execution within those Pods. If a user can be… | |
| Analizada | Media (4.8) | 0.36% | — | Argoproj Argo Workflows | 28/10/2024 | 17/6/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to a race condition in a global variable in 3.6.0-rc1, the argo workflows controller can be made to crash on-command by any user with access to execute a workflow. This vulnerability is fixed in… | |
| Modificada | Media (5.4) | 0.75% | — | Jenkins Template Workflows | 14/6/2023 | 17/6/2026 | Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs. | |
| Modificada | Alta (8.8) | 1.3% | — | Kartverket Github-workflows | 25/10/2022 | 17/6/2026 | kartverket/github-workflows are shared reusable workflows for GitHub Actions. Prior to version 2.7.5, all users of the `run-terraform` reusable workflow from the kartverket/github-workflows repo are affected by a code injection vulnerability. A malicious actor could potentially send a PR with a malicious payload… | |
| Modificada | Alta (7.1) | 0.92% | — | Argoproj Argo Workflows | 6/5/2022 | 17/6/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affected versions an attacker can create a workflow which produces a HTML artifact containing an HTML file that contains a script which uses XHR calls to interact with the Argo Server API. The attacker… | |
| Analizada | Media (6.5) | 0.96% | — | Argoproj Argo Workflows | 3/8/2021 | 17/6/2026 | In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated. |