CVE-2026-40886
published 2026-04-23CVE-2026-40886: Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index…
high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pod-gc-strategy annotation. Because the panic occurs inside an informer goroutine (outside the controller's recover() scope), it crashes the entire controller process. The poisoned pod persists across restarts, causing a crash loop that halts all workflow processing until the pod is manually deleted. This vulnerability is fixed in 4.0.5 and 3.7.14.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| argoproj | argo-workflows | — | — |
| argoproj | argo-workflows | — | — |
| argoproj | argo-workflows | — | — |
| argoproj | argo_workflows | 3.6.5 – 3.6.19 | — |
| argoproj | argo_workflows | >= 3.7.0 < 3.7.14 | 3.7.14 |
| argoproj | argo_workflows | >= 4.0.0 < 4.0.5 | 4.0.5 |
| github.com | argoproj_argo-workflows_v3 | 3.6.5 – 3.6.19 | — |
| github.com | argoproj_argo-workflows_v3 | >= 3.7.0 < 3.7.14 | 3.7.14 |
| github.com | argoproj_argo-workflows_v4 | >= 4.0.0 < 4.0.5 | 4.0.5 |
| rhoai | odh-data-science-pipelines-argo-argoexec-rhel8 | — | — |
| rhoai | odh-data-science-pipelines-argo-argoexec-rhel9 | — | — |
| rhoai | odh-data-science-pipelines-argo-workflowcontroller-rhel8 | — | — |
| rhoai | odh-data-science-pipelines-argo-workflowcontroller-rhel9 | — | — |
| rhoai | odh-ml-pipelines-api-server-v2-rhel8 | — | — |
| rhoai | odh-ml-pipelines-api-server-v2-rhel9 | — | — |
| rhoai | odh-ml-pipelines-driver-rhel8 | — | — |
| rhoai | odh-ml-pipelines-driver-rhel9 | — | — |
| rhoai | odh-ml-pipelines-launcher-rhel8 | — | — |
| rhoai | odh-ml-pipelines-launcher-rhel9 | — | — |
| rhoai | odh-ml-pipelines-persistenceagent-v2-rhel8 | — | — |
| rhoai | odh-ml-pipelines-persistenceagent-v2-rhel9 | — | — |
| rhoai | odh-ml-pipelines-scheduledworkflow-v2-rhel8 | — | — |
| rhoai | odh-ml-pipelines-scheduledworkflow-v2-rhel9 | — | — |