PT-2026-37192 · Unknown · Argo Workflows

Rudra2018

·

Published

2026-05-04

·

Updated

2026-05-14

·

CVE-2026-42294

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Argo Workflows versions prior to 3.7.14 Argo Workflows versions prior to 4.0.5
Description The Webhook Interceptor loads the entire request body into memory before authenticating the request or verifying its signature. This occurs on the '/api/v1/events/' endpoint, which is publicly accessible. An attacker can send a request with an extremely large body, causing the Argo Server to allocate excessive memory, which may lead to an Out-Of-Memory (OOM) crash and denial of service. This issue is located in the addWebhookAuthorization() function within the server/auth/webhook component.
Recommendations Update to version 3.7.14 or later. Update to version 4.0.5 or later. Enforce a strict limit on webhook body size using http.MaxBytesReader. Implement streaming verification for signatures or use temporary files for large payloads.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ARGO-WORKFLOWS-2026-42294
CVE-2026-42294
GHSA-JCC8-G2Q4-9FXQ

Affected Products

Argo Workflows