HIGH GitHub

CVE-2026-54526

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

### Summary The allow-list fix for CVE-2026-31892 (GHSA-3wf5-g532-rcrr), and its follow-up coverage of `hostNetwork`/`securityContext`/`serviceAccountName` in GHSA-3775-99mw-8rp4, is incomplete. `workflow/util/merge.go` `ValidateUserOverrides` / `SanitizeUserWorkflowSpec` walk only the top-level fields of `WorkflowSpec` via reflection. `WorkflowSpec.ArtifactGC` is allow-listed because admins want users to configure artifact garbage collection. The struct behind that field, `WorkflowLevelArtifac

Affected Products

References

Published: 2026-08-13 · Source: GitHub · Feed updated: 2026-08-13
This high severity vulnerability was published on 2026-08-13 via GitHub. Affected: go/github.com/argoproj/argo-workflows/v4 >= 4.0.0, < 4.0.6, go/github.com/argoproj/argo-workflows/v3 < 3.7.15, go/github.com/argoproj/argo-workflows <= 2.5.3-rc4.
vulnfeed aggregates 10617 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.