HIGH GitHub
CVE-2026-54526
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
### Summary
The allow-list fix for CVE-2026-31892 (GHSA-3wf5-g532-rcrr), and its follow-up coverage of `hostNetwork`/`securityContext`/`serviceAccountName` in GHSA-3775-99mw-8rp4, is incomplete. `workflow/util/merge.go` `ValidateUserOverrides` / `SanitizeUserWorkflowSpec` walk only the top-level fields of `WorkflowSpec` via reflection. `WorkflowSpec.ArtifactGC` is allow-listed because admins want users to configure artifact garbage collection. The struct behind that field, `WorkflowLevelArtifac
Affected Products
- go/github.com/argoproj/argo-workflows/v4 >= 4.0.0, < 4.0.6
- go/github.com/argoproj/argo-workflows/v3 < 3.7.15
- go/github.com/argoproj/argo-workflows <= 2.5.3-rc4
References
- https://github.com/advisories/GHSA-48p8-g2fx-3wwm
- https://github.com/argoproj/argo-workflows/security/advisories/GHSA-48p8-g2fx-3wwm
- https://nvd.nist.gov/vuln/detail/CVE-2026-54526
- https://github.com/argoproj/argo-workflows/commit/277e9cef0ad16d7eaaab253573d0695951a65dbd
This high severity vulnerability was published on 2026-08-13 via GitHub. Affected: go/github.com/argoproj/argo-workflows/v4 >= 4.0.0, < 4.0.6, go/github.com/argoproj/argo-workflows/v3 < 3.7.15, go/github.com/argoproj/argo-workflows <= 2.5.3-rc4.
vulnfeed aggregates 10617 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.