Snyk - Open Source Security

Snyk test report

August 30th 2026, 12:33:37 am (UTC+00:00)

Scanned the following paths:
  • /argo-cd/argoproj/argo-cd/v3/go.mod (gomodules)
  • /argo-cd/argoproj/argo-cd/gitops-engine/v3/gitops-engine/go.mod (gomodules)
  • /argo-cd/argoproj/argo-cd/get-previous-release/hack/get-previous-release/go.mod (gomodules)
  • /argo-cd/ui/pnpm-lock.yaml (pnpm)
19 known vulnerabilities
111 vulnerable dependency paths
3000 dependencies

Regular Expression Denial of Service (ReDoS)

high severity
Exploit: Not Defined

  • Manifest file: /argo-cd ui/pnpm-lock.yaml
  • Package Manager: npm
  • Vulnerable module: linkify-it
  • Introduced through: argo-cd-ui@1.0.0, ansi-to-react@6.2.6 and others

Detailed paths

  • Introduced through: argo-cd-ui@1.0.0 ansi-to-react@6.2.6 linkify-it@3.0.3

Overview

linkify-it is a Links recognition library with FULL unicode support

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to quadratic algorithmic complexity in the match function. An attacker can exhaust CPU resources and cause significant delays in processing by submitting specially crafted input containing a large number of email-like or link-like strings.

Details

Denial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its original and legitimate users. There are many types of DoS attacks, ranging from trying to clog the network pipes to the system by generating a large volume of traffic from many machines (a Distributed Denial of Service - DDoS - attack) to sending crafted requests that cause a system to crash or take a disproportional amount of time to process.

The Regular expression Denial of Service (ReDoS) is a type of Denial of Service attack. Regular expressions are incredibly powerful, but they aren't very intuitive and can ultimately end up making it easy for attackers to take your site down.

Let’s take the following regular expression as an example:

regex = /A(B|C+)+D/
        

This regular expression accomplishes the following:

  • A The string must start with the letter 'A'
  • (B|C+)+ The string must then follow the letter A with either the letter 'B' or some number of occurrences of the letter 'C' (the + matches one or more times). The + at the end of this section states that we can look for one or more matches of this section.
  • D Finally, we ensure this section of the string ends with a 'D'

The expression would match inputs such as ABBD, ABCCCCD, ABCBCCCD and ACCCCCD

It most cases, it doesn't take very long for a regex engine to find a match:

$ time node -e '/A(B|C+)+D/.test("ACCCCCCCCCCCCCCCCCCCCCCCCCCCCD")'
        0.04s user 0.01s system 95% cpu 0.052 total
        
        $ time node -e '/A(B|C+)+D/.test("ACCCCCCCCCCCCCCCCCCCCCCCCCCCCX")'
        1.79s user 0.02s system 99% cpu 1.812 total
        

The entire process of testing it against a 30 characters long string takes around ~52ms. But when given an invalid string, it takes nearly two seconds to complete the test, over ten times as long as it took to test a valid string. The dramatic difference is due to the way regular expressions get evaluated.

Most Regex engines will work very similarly (with minor differences). The engine will match the first possible way to accept the current character and proceed to the next one. If it then fails to match the next one, it will backtrack and see if there was another way to digest the previous character. If it goes too far down the rabbit hole only to find out the string doesn’t match in the end, and if many characters have multiple valid regex paths, the number of backtracking steps can become very large, resulting in what is known as catastrophic backtracking.

Let's look at how our expression runs into this problem, using a shorter string: "ACCCX". While it seems fairly straightforward, there are still four different ways that the engine could match those three C's:

  1. CCC
  2. CC+C
  3. C+CC
  4. C+C+C.

The engine has to try each of those combinations to see if any of them potentially match against the expression. When you combine that with the other steps the engine must take, we can use RegEx 101 debugger to see the engine has to take a total of 38 steps before it can determine the string doesn't match.

From there, the number of steps the engine must use to validate a string just continues to grow.

String Number of C's Number of steps
ACCCX 3 38
ACCCCX 4 71
ACCCCCX 5 136
ACCCCCCCCCCCCCCX 14 65,553

By the time the string includes 14 C's, the engine has to take over 65,000 steps just to see if the string is valid. These extreme situations can cause them to work very slowly (exponentially related to input size, as shown above), allowing an attacker to exploit this and can cause the service to excessively consume CPU, resulting in a Denial of Service.

Remediation

Upgrade linkify-it to version 5.0.1 or higher.

References


Inefficient Algorithmic Complexity

high severity
Exploit: Proof of Concept

  • Manifest file: /argo-cd ui/pnpm-lock.yaml
  • Package Manager: npm
  • Vulnerable module: linkify-it
  • Introduced through: argo-cd-ui@1.0.0, ansi-to-react@6.2.6 and others

Detailed paths

  • Introduced through: argo-cd-ui@1.0.0 ansi-to-react@6.2.6 linkify-it@3.0.3

Overview

linkify-it is a Links recognition library with FULL unicode support

Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the mailto: validator scan-loop on attacker-supplied text. An attacker can cause excessive CPU consumption by submitting specially crafted input that triggers repeated scanning of the remaining text.

Remediation

Upgrade linkify-it to version 5.0.2 or higher.

References


Directory Traversal

high severity
Exploit: Not Defined

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Vulnerable module: github.com/go-git/go-git/v5/storage/filesystem/dotgit
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0, github.com/go-git/go-git/v5@5.19.1 and others

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1

Overview

Affected versions of this package are vulnerable to Directory Traversal via the processing of reference names in dotgit. An attacker can modify or overwrite files outside the intended reference storage by supplying specially crafted reference names containing path traversal sequences. This is only exploitable if the application uses filesystem-backed storage and interacts with a malicious Git server or processes attacker-controlled reference names.

Workaround

This vulnerability can be mitigated by exclusively using in-memory storage or by validating reference names at the application level before passing them to filesystem-backed storage.

Details

A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and its variations, or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system, including application source code, configuration, and other critical system files.

Directory Traversal vulnerabilities can be generally divided into two types:

  • Information Disclosure: Allows the attacker to gain information about the folder structure or read the contents of sensitive files on the system.

st is a module for serving static files on web pages, and contains a vulnerability of this type. In our example, we will serve files from the public route.

If an attacker requests the following URL from our server, it will in turn leak the sensitive private key of the root user.

curl http://localhost:8080/public/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/root/.ssh/id_rsa
        

Note %2e is the URL encoded version of . (dot).

  • Writing arbitrary files: Allows the attacker to create or replace existing files. This type of vulnerability is also known as Zip-Slip.

One way to achieve this is by using a malicious zip archive that holds path traversal filenames. When each filename in the zip archive gets concatenated to the target extraction folder, without validation, the final path ends up outside of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily.

The following is an example of a zip archive with one benign file and one malicious file. Extracting the malicious file will result in traversing out of the target folder, ending up in /root/.ssh/ overwriting the authorized_keys file:

2018-04-15 22:04:29 .....           19           19  good.txt
        2018-04-15 22:04:42 .....           20           20  ../../../../../../root/.ssh/authorized_keys
        

Remediation

Upgrade github.com/go-git/go-git/v5/storage/filesystem/dotgit to version 5.19.2 or higher.

References


Directory Traversal

high severity
Exploit: Not Defined

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Vulnerable module: github.com/go-git/go-git/v5/plumbing
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 and github.com/go-git/go-git/v5/plumbing@5.19.1

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/config@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/utils/merkletrie/filesystem@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/config@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/utils/merkletrie/index@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing/format/packfile@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing/format/objfile@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/config@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing/format/packfile@5.19.1 github.com/go-git/go-git/v5/plumbing/cache@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/plumbing/revlist@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing/format/packfile@5.19.1 github.com/go-git/go-git/v5/plumbing/format/idxfile@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/utils/merkletrie/index@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/utils/binary@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/config@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/plumbing/revlist@5.19.1 github.com/go-git/go-git/v5/plumbing/object@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/plumbing/revlist@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/utils/binary@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing/format/packfile@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/plumbing/revlist@5.19.1 github.com/go-git/go-git/v5/plumbing/object@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/plumbing/revlist@5.19.1 github.com/go-git/go-git/v5/plumbing/object@5.19.1 github.com/go-git/go-git/v5/plumbing/format/diff@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing/format/objfile@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/config@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/config@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing/format/packfile@5.19.1 github.com/go-git/go-git/v5/plumbing/cache@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/plumbing/revlist@5.19.1 github.com/go-git/go-git/v5/plumbing/object@5.19.1 github.com/go-git/go-git/v5/plumbing/format/diff@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/file@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/server@5.19.1 github.com/go-git/go-git/v5/storage/filesystem@5.19.1 github.com/go-git/go-git/v5/storage/filesystem/dotgit@5.19.1 github.com/go-git/go-git/v5/plumbing/format/packfile@5.19.1 github.com/go-git/go-git/v5/plumbing/format/idxfile@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/utils/binary@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/config@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/utils/binary@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/http@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/utils/binary@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5/plumbing/transport/client@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/ssh@5.19.1 github.com/go-git/go-git/v5/plumbing/transport/internal/common@5.19.1 github.com/go-git/go-git/v5/plumbing/transport@5.19.1 github.com/go-git/go-git/v5/plumbing/protocol/packp@5.19.1 github.com/go-git/go-git/v5/storage/memory@5.19.1 github.com/go-git/go-git/v5/storage@5.19.1 github.com/go-git/go-git/v5/plumbing/storer@5.19.1 github.com/go-git/go-git/v5/plumbing/format/index@5.19.1 github.com/go-git/go-git/v5/utils/binary@5.19.1 github.com/go-git/go-git/v5/plumbing@5.19.1

Overview

github.com/go-git/go-git/v5/plumbing is a highly extensible git implementation library written in pure Go.

Affected versions of this package are vulnerable to Directory Traversal via the processing of reference names in dotgit. An attacker can modify or overwrite files outside the intended reference storage by supplying specially crafted reference names containing path traversal sequences. This is only exploitable if the application uses filesystem-backed storage and interacts with a malicious Git server or processes attacker-controlled reference names.

Workaround

This vulnerability can be mitigated by exclusively using in-memory storage or by validating reference names at the application level before passing them to filesystem-backed storage.

Details

A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and its variations, or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system, including application source code, configuration, and other critical system files.

Directory Traversal vulnerabilities can be generally divided into two types:

  • Information Disclosure: Allows the attacker to gain information about the folder structure or read the contents of sensitive files on the system.

st is a module for serving static files on web pages, and contains a vulnerability of this type. In our example, we will serve files from the public route.

If an attacker requests the following URL from our server, it will in turn leak the sensitive private key of the root user.

curl http://localhost:8080/public/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/root/.ssh/id_rsa
        

Note %2e is the URL encoded version of . (dot).

  • Writing arbitrary files: Allows the attacker to create or replace existing files. This type of vulnerability is also known as Zip-Slip.

One way to achieve this is by using a malicious zip archive that holds path traversal filenames. When each filename in the zip archive gets concatenated to the target extraction folder, without validation, the final path ends up outside of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily.

The following is an example of a zip archive with one benign file and one malicious file. Extracting the malicious file will result in traversing out of the target folder, ending up in /root/.ssh/ overwriting the authorized_keys file:

2018-04-15 22:04:29 .....           19           19  good.txt
        2018-04-15 22:04:42 .....           20           20  ../../../../../../root/.ssh/authorized_keys
        

Remediation

Upgrade github.com/go-git/go-git/v5/plumbing to version 5.19.2 or higher.

References


Symlink Attack

high severity
Exploit: Not Defined

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Vulnerable module: github.com/go-git/go-git/v5
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 and github.com/go-git/go-git/v5@5.19.1

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-git/go-git/v5@5.19.1

Overview

Affected versions of this package are vulnerable to Symlink Attack in worktree_fs.go and worktree.go are vulnerable to symlink traversal in filesystem-backed worktrees. An attacker can modify or overwrite files outside the intended worktree by placing a symlink in the tree and then triggering a worktree operation, such as checkout, create, rename, or remove, against a path that resolves through that link. This can redirect writes into the repository’s .git metadata or another external target, leading to arbitrary file write and corruption of repository state, which can break subsequent Git operations and expose or alter files the application did not intend to touch.

Remediation

Upgrade github.com/go-git/go-git/v5 to version 5.19.2 or higher.

References


Inefficient Algorithmic Complexity

high severity
Exploit: Not Defined

  • Manifest file: /argo-cd ui/pnpm-lock.yaml
  • Package Manager: npm
  • Vulnerable module: brace-expansion
  • Introduced through: argo-cd-ui@1.0.0, argo-ui@1.0.0 and others

Detailed paths

  • Introduced through: argo-cd-ui@1.0.0 argo-ui@1.0.0 minimatch@9.0.9 brace-expansion@2.1.0
  • Introduced through: argo-cd-ui@1.0.0 minimatch@3.1.5 brace-expansion@1.1.14

Overview

brace-expansion is a Brace expansion as known from sh/bash

Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity via the expand function. An attacker can cause excessive CPU consumption and block the event loop by supplying a specially crafted string containing multiple consecutive non-expanding '{}' brace groups. The max option does not prevent this issue, as it only limits the output size and not the computational workload.

Remediation

Upgrade brace-expansion to version 1.1.16, 2.1.2, 5.0.7 or higher.

References


Allocation of Resources Without Limits or Throttling

high severity
Exploit: Proof of Concept

  • Manifest file: /argo-cd ui/pnpm-lock.yaml
  • Package Manager: npm
  • Vulnerable module: brace-expansion
  • Introduced through: argo-cd-ui@1.0.0, argo-ui@1.0.0 and others

Detailed paths

  • Introduced through: argo-cd-ui@1.0.0 argo-ui@1.0.0 minimatch@9.0.9 brace-expansion@2.1.0
  • Introduced through: argo-cd-ui@1.0.0 minimatch@3.1.5 brace-expansion@1.1.14

Overview

brace-expansion is a Brace expansion as known from sh/bash

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the expand() function and its recursive expand_ helper, which cap the number of results via the max option but do not bound the length of each result string. An attacker can crash the Node process with a fatal, uncatchable out-of-memory error by supplying a pattern that chains many brace groups, such as {a,b} repeated, keeping the result count under max while each result grows with the group count so total output scales unbounded. Exploitation requires the application to pass untrusted input to expand(), directly or transitively through minimatch or glob brace patterns.

Workaround

This vulnerability can be avoided by passing small explicit max and maxLength options to expand(), bounding both the number of results and the length of each so total output stays limited.

Remediation

Upgrade brace-expansion to version 1.1.16, 2.1.2, 5.0.8 or higher.

References


Allocation of Resources Without Limits or Throttling

high severity
Exploit: Proof of Concept

  • Manifest file: /argo-cd ui/pnpm-lock.yaml
  • Package Manager: npm
  • Vulnerable module: brace-expansion
  • Introduced through: argo-cd-ui@1.0.0, argo-ui@1.0.0 and others

Detailed paths

  • Introduced through: argo-cd-ui@1.0.0 argo-ui@1.0.0 minimatch@9.0.9 brace-expansion@2.1.0
  • Introduced through: argo-cd-ui@1.0.0 minimatch@3.1.5 brace-expansion@1.1.14

Overview

brace-expansion is a Brace expansion as known from sh/bash

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the expand(), expand_(), combine(), and expandSequence() functions, which bound the accumulator where results are combined but not the intermediate arrays that feed it. An attacker can crash the process with an uncatchable out-of-memory error, or stall the event loop for minutes, by supplying a pattern with many comma-separated alternatives that each receive an independent maxLength allowance and accumulate without a cumulative limit, or a padded sequence whose generation ignores maxLength and does work proportional to max * width. Exploitation requires the application to pass untrusted input to expand(), directly or transitively through a glob or pattern-matching library.

Workaround

This vulnerability can be avoided by passing an explicitly small max together with a small maxLength to expand(), bounding both the result count and length, since a small maxLength alone is insufficient on affected versions where it is applied per alternative rather than cumulatively.

Note: This is a bypass of the fix for the vulnerability described in CVE-2026-14257.

Remediation

Upgrade brace-expansion to version 1.1.18, 2.1.4, 3.0.6, 5.0.9 or higher.

References


Improper Validation of Specified Index, Position, or Offset in Input

medium severity
Exploit: Proof of Concept

  • Manifest file: /argo-cd ui/pnpm-lock.yaml
  • Package Manager: npm
  • Vulnerable module: uuid
  • Introduced through: argo-cd-ui@1.0.0, argo-ui@1.0.0 and others

Detailed paths

  • Introduced through: argo-cd-ui@1.0.0 argo-ui@1.0.0 uuid@9.0.1

Overview

uuid is a RFC4122 (v1, v4, and v5) compliant UUID library.

Affected versions of this package are vulnerable to Improper Validation of Specified Index, Position, or Offset in Input due to accepting external output buffers but not rejecting out-of-range writes (small buf or large offset). This inconsistency allows silent partial writes into caller-provided buffers.

PoC

cd /home/StrawHat/uuid
        npm ci
        npm run build
        
        node --input-type=module -e "
        import {v4,v5,v6} from './dist-node/index.js';
        const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';
        for (const [name,fn] of [
          ['v4',()=>v4({},new Uint8Array(8),4)],
          ['v5',()=>v5('x',ns,new Uint8Array(8),4)],
          ['v6',()=>v6({},new Uint8Array(8),4)],
        ]) {
          try { fn(); console.log(name,'NO_THROW'); }
          catch(e){ console.log(name,'THREW',e.name); }
        }"
        

Remediation

Upgrade uuid to version 11.1.1, 14.0.0 or higher.

References


Memory Allocation with Excessive Size Value

medium severity
Exploit: Proof of Concept

  • Manifest file: /argo-cd/argoproj/argo-cd/gitops-engine/v3 gitops-engine/go.mod
  • Package Manager: golang
  • Vulnerable module: go.opentelemetry.io/otel/propagation
  • Introduced through: github.com/argoproj/argo-cd/gitops-engine/v3@0.0.0, go.opentelemetry.io/otel@1.41.0 and others

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/gitops-engine/v3@0.0.0 go.opentelemetry.io/otel@1.41.0 go.opentelemetry.io/otel/propagation@1.41.0
  • Introduced through: github.com/argoproj/argo-cd/gitops-engine/v3@0.0.0 go.opentelemetry.io/otel@1.41.0 go.opentelemetry.io/otel/internal/global@1.41.0 go.opentelemetry.io/otel/propagation@1.41.0

Overview

Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value via the Parse function. An attacker can exhaust CPU resources and generate excessive log output by sending oversized or malformed headers that are processed without length checks.

Remediation

Upgrade go.opentelemetry.io/otel/propagation to version 1.44.0 or higher.

References


Memory Allocation with Excessive Size Value

medium severity
Exploit: Proof of Concept

  • Manifest file: /argo-cd/argoproj/argo-cd/gitops-engine/v3 gitops-engine/go.mod
  • Package Manager: golang
  • Vulnerable module: go.opentelemetry.io/otel/baggage
  • Introduced through: github.com/argoproj/argo-cd/gitops-engine/v3@0.0.0, go.opentelemetry.io/otel@1.41.0 and others

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/gitops-engine/v3@0.0.0 go.opentelemetry.io/otel@1.41.0 go.opentelemetry.io/otel/propagation@1.41.0 go.opentelemetry.io/otel/baggage@1.41.0

Overview

Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value via the Parse function. An attacker can exhaust CPU resources and generate excessive log output by sending oversized or malformed headers that are processed without length checks.

Remediation

Upgrade go.opentelemetry.io/otel/baggage to version 1.44.0 or higher.

References


Improper Validation of Specified Type of Input

medium severity
Exploit: Not Defined

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Vulnerable module: github.com/vmihailenco/msgpack/v5
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0, github.com/go-redis/cache/v9@9.0.0 and others

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/go-redis/cache/v9@9.0.0 github.com/vmihailenco/msgpack/v5@5.4.1
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/r3labs/diff/v3@3.0.2 github.com/vmihailenco/msgpack/v5@5.4.1

Overview

Affected versions of this package are vulnerable to Improper Validation of Specified Type of Input in the calls plugin when handling websocket messages containing malformed msgpack frames. An attacker can cause the server to consume excessive memory and crash by sending specially crafted websocket requests.

Remediation

There is no fixed version for github.com/vmihailenco/msgpack/v5.

References


MPL-2.0 license

medium severity

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Module: github.com/r3labs/diff/v3
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 and github.com/r3labs/diff/v3@3.0.2

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/r3labs/diff/v3@3.0.2

MPL-2.0 license


MPL-2.0 license

medium severity

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Module: github.com/hashicorp/go-version
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0, code.gitea.io/sdk/gitea@0.25.1 and others

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 code.gitea.io/sdk/gitea@0.25.1 github.com/hashicorp/go-version@1.9.0

MPL-2.0 license


MPL-2.0 license

medium severity

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Module: github.com/hashicorp/go-retryablehttp
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 and github.com/hashicorp/go-retryablehttp@0.7.8

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 gitlab.com/gitlab-org/api/client-go@1.46.0 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/cmd@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/api@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/controller@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/cmd@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/api@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/controller@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8

MPL-2.0 license


MPL-2.0 license

medium severity

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Module: github.com/hashicorp/go-cleanhttp
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0, github.com/hashicorp/go-retryablehttp@0.7.8 and others

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/hashicorp/go-retryablehttp@0.7.8 github.com/hashicorp/go-cleanhttp@0.5.2
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 gitlab.com/gitlab-org/api/client-go@1.46.0 github.com/hashicorp/go-cleanhttp@0.5.2
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 gitlab.com/gitlab-org/api/client-go@1.46.0 github.com/hashicorp/go-retryablehttp@0.7.8 github.com/hashicorp/go-cleanhttp@0.5.2
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8 github.com/hashicorp/go-cleanhttp@0.5.2
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/cmd@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8 github.com/hashicorp/go-cleanhttp@0.5.2
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8 github.com/hashicorp/go-cleanhttp@0.5.2
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/api@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8 github.com/hashicorp/go-cleanhttp@0.5.2
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/argoproj/notifications-engine/pkg/controller@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/subscriptions@#0cff13b8a717 github.com/argoproj/notifications-engine/pkg/services@#0cff13b8a717 github.com/opsgenie/opsgenie-go-sdk-v2/client@1.2.23 github.com/hashicorp/go-retryablehttp@0.7.8 github.com/hashicorp/go-cleanhttp@0.5.2

MPL-2.0 license


MPL-2.0 license

medium severity

  • Manifest file: /argo-cd/argoproj/argo-cd/v3 go.mod
  • Package Manager: golang
  • Module: github.com/gosimple/slug
  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 and github.com/gosimple/slug@1.15.0

Detailed paths

  • Introduced through: github.com/argoproj/argo-cd/v3@0.0.0 github.com/gosimple/slug@1.15.0

MPL-2.0 license


Regular Expression Denial of Service (ReDoS)

medium severity
Exploit: Proof of Concept

  • Manifest file: /argo-cd ui/pnpm-lock.yaml
  • Package Manager: npm
  • Vulnerable module: foundation-sites
  • Introduced through: argo-cd-ui@1.0.0 and foundation-sites@6.9.0

Detailed paths

  • Introduced through: argo-cd-ui@1.0.0 foundation-sites@6.9.0
  • Introduced through: argo-cd-ui@1.0.0 argo-ui@1.0.0 foundation-sites@6.9.0

Overview

foundation-sites is a responsive front-end framework

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to inefficient backtracking in the regular expressions used in URL forms.

PoC

https://www.''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
        

Details

Denial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its original and legitimate users. There are many types of DoS attacks, ranging from trying to clog the network pipes to the system by generating a large volume of traffic from many machines (a Distributed Denial of Service - DDoS - attack) to sending crafted requests that cause a system to crash or take a disproportional amount of time to process.

The Regular expression Denial of Service (ReDoS) is a type of Denial of Service attack. Regular expressions are incredibly powerful, but they aren't very intuitive and can ultimately end up making it easy for attackers to take your site down.

Let’s take the following regular expression as an example:

regex = /A(B|C+)+D/
        

This regular expression accomplishes the following:

  • A The string must start with the letter 'A'
  • (B|C+)+ The string must then follow the letter A with either the letter 'B' or some number of occurrences of the letter 'C' (the + matches one or more times). The + at the end of this section states that we can look for one or more matches of this section.
  • D Finally, we ensure this section of the string ends with a 'D'

The expression would match inputs such as ABBD, ABCCCCD, ABCBCCCD and ACCCCCD

It most cases, it doesn't take very long for a regex engine to find a match:

$ time node -e '/A(B|C+)+D/.test("ACCCCCCCCCCCCCCCCCCCCCCCCCCCCD")'
        0.04s user 0.01s system 95% cpu 0.052 total
        
        $ time node -e '/A(B|C+)+D/.test("ACCCCCCCCCCCCCCCCCCCCCCCCCCCCX")'
        1.79s user 0.02s system 99% cpu 1.812 total
        

The entire process of testing it against a 30 characters long string takes around ~52ms. But when given an invalid string, it takes nearly two seconds to complete the test, over ten times as long as it took to test a valid string. The dramatic difference is due to the way regular expressions get evaluated.

Most Regex engines will work very similarly (with minor differences). The engine will match the first possible way to accept the current character and proceed to the next one. If it then fails to match the next one, it will backtrack and see if there was another way to digest the previous character. If it goes too far down the rabbit hole only to find out the string doesn’t match in the end, and if many characters have multiple valid regex paths, the number of backtracking steps can become very large, resulting in what is known as catastrophic backtracking.

Let's look at how our expression runs into this problem, using a shorter string: "ACCCX". While it seems fairly straightforward, there are still four different ways that the engine could match those three C's:

  1. CCC
  2. CC+C
  3. C+CC
  4. C+C+C.

The engine has to try each of those combinations to see if any of them potentially match against the expression. When you combine that with the other steps the engine must take, we can use RegEx 101 debugger to see the engine has to take a total of 38 steps before it can determine the string doesn't match.

From there, the number of steps the engine must use to validate a string just continues to grow.

String Number of C's Number of steps
ACCCX 3 38
ACCCCX 4 71
ACCCCCX 5 136
ACCCCCCCCCCCCCCX 14 65,553

By the time the string includes 14 C's, the engine has to take over 65,000 steps just to see if the string is valid. These extreme situations can cause them to work very slowly (exponentially related to input size, as shown above), allowing an attacker to exploit this and can cause the service to excessively consume CPU, resulting in a Denial of Service.

Remediation

There is no fixed version for foundation-sites.

References


CRLF Injection

medium severity
Exploit: Proof of Concept

  • Manifest file: /argo-cd ui/pnpm-lock.yaml
  • Package Manager: npm
  • Vulnerable module: form-data
  • Introduced through: argo-cd-ui@1.0.0, superagent@8.1.2 and others

Detailed paths

  • Introduced through: argo-cd-ui@1.0.0 superagent@8.1.2 form-data@4.0.5

Overview

Affected versions of this package are vulnerable to CRLF Injection via the _multiPartHeader function when untrusted input is provided via field or filename to FormData#append. An attacker can inject additional headers or multipart parts by including carriage returns, line feeds, or double quotes in the input. This can allow the modification or addition of form fields visible to downstream parsers.

PoC

const FormData = require('form-data');
        const form = new FormData();
        form.append('email"\r\nX-Injected: true\r\nfake="', 'user@example.com');
        console.log(form.getBuffer().toString());
        

Remediation

Upgrade form-data to version 2.5.6, 3.0.5, 4.0.6 or higher.

References