Vulnerability Report: GO-2025-3996
- CVE-2025-59537, GHSA-wp4p-9pxh-cgx2
- Affects: github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2, and 1 more
- Published: Oct 23, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd
For detailed information about this vulnerability, visit https://github.com/argoproj/argo-cd/security/advisories/GHSA-wp4p-9pxh-cgx2 or https://nvd.nist.gov/vuln/detail/CVE-2025-59537.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-wp4p-9pxh-cgx2
- https://nvd.nist.gov/vuln/detail/CVE-2025-59537
- https://github.com/argoproj/argo-cd/commit/761fc27068d2d4cd24e1f784eb2a9033b5ee7f43
- https://vuln.go.dev/ID/GO-2025-3996.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.