CVE-2026-40886Disclosure(argoproj / argo_workflows)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pod-gc-strategy annotation. Because the panic occurs inside an informer goroutine (outside the controller's recover() scope), it crashes the entire controller process. The poisoned pod persists across restarts, causing a crash loop that halts all workflow processing until the pod is manually deleted. This vulnerability is fixed in 4.0.5 and 3.7.14.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129CWE-1285

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • argo_workflows

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-23); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
argo_workflows

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-28: 104-2304-2404-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40886: CVE-2026-40886: Denial of Service via Unchecked Annotation Parsing in Argo Workflows CVE-2026-40886 is a high-severity denial-of-service vulnerability in Argo Workflows caused by an unhandled Go runtime panic. A malformed Kubernetes an... https://cvereports.com/reports/CVE-2026-40886

    Post summary

    The post announces a high-severity denial-of-service vulnerability in Argo Workflows caused by unhandled Go runtime panics, providing basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0000022
    36 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Argo Workflows, Unchecked Array Index, #CVE-2026-40886 (Critical) https://dailycve.com/argo-workflows-unchecked-array-index-cve-2026-40886-critical/

    Post summary

    The link points to a DailyCVE announcement of a critical unchecked array index vulnerability in Argo Workflows (CVE‑2026‑40886), but no PoC, exploit, patch, or evidence of active exploitation is referenced.

    0000055
    183 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40886 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the … https://www.cve.org/CVERecord?id=CVE-2026-40886

    Post summary

    CVE-2026-40886 reveals an unchecked array index flaw in Argo Workflows across versions 3.6.5 to 4.0.4, but no PoC, exploit, or patch information is provided.

    0000095
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appargoprojargo_workflows-go-

Explore more