CVE Vulnerabilities

CVE-2025-59531

Improper Check or Handling of Exceptional Conditions

Published: Oct 01, 2025 | Modified: Oct 07, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CDs /api/webhook endpoint crashes when receiving a malformed Bitbucket Server payload (non-array repository.links.clone field). A single unauthenticated request triggers CrashLoopBackOff, and targeting all replicas causes complete API outage. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.

Weakness

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Affected Software

Name Vendor Start Version End Version
Argo_cd Argoproj 1.2.0 (including) 1.8.7 (including)
Argo_cd Argoproj 2.0.0 (including) 2.14.20 (excluding)
Argo_cd Argoproj 3.0.0 (including) 3.0.19 (excluding)
Argo_cd Argoproj 3.1.0 (including) 3.1.8 (excluding)
Argo_cd Argoproj 3.2.0-rc1 (including) 3.2.0-rc1 (including)

References