Vulnerability Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. With the default configuration, no webhook.gogs.secret set, Argo CD’s /api/webhook endpoint will crash the entire argocd-server process when it receives a Gogs push event whose JSON field commits[].repo is not set or is null. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Argoproj | Argo Cd | >= 1.2.0, <= 1.8.7 |
Related Weaknesses (CWE)
References
- https://github.com/argoproj/argo-cd/commit/761fc27068d2d4cd24e1f784eb2a9033b5ee7Patch
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-wp4p-9pxh-cgx2ExploitMitigationVendor Advisory
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-wp4p-9pxh-cgx2ExploitMitigationVendor Advisory
FAQ
What is CVE-2025-59537?
CVE-2025-59537 is a vulnerability with a CVSS score of 7.5 (HIGH). Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malic...
How severe is CVE-2025-59537?
CVE-2025-59537 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59537?
Check the references section above for vendor advisories and patch information. Affected products include: Argoproj Argo Cd.