
🔴 Wasmtime, Bulk Memory Operation State Corruption, #CVE-2025-59531 (High) -DC-Oct2026-2714 https://dailycve.com/wasmtime-bulk-memory-operation-state-corruption-cve-2025-59531-high-dc-oct2026-2714/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CD's /api/webhook endpoint crashes when receiving a malformed Bitbucket Server payload (non-array repository.links.clone field). A single unauthenticated request triggers CrashLoopBackOff, and targeting all replicas causes complete API outage. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

🔴 Wasmtime, Bulk Memory Operation State Corruption, #CVE-2025-59531 (High) -DC-Oct2026-2714 https://dailycve.com/wasmtime-bulk-memory-operation-state-corruption-cve-2025-59531-high-dc-oct2026-2714/
2 of 2 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | argoproj | argo_cd | - | - | - |
| App | argoproj | argo_cd | 3.2.0 | - | - |