
Read-only access in ArgoCD and you can extract every plaintext Kubernetes secret in the cluster. That's CVE-2026-43824 / GHSA-3v3m-wc6v-x4x3, and it's bad. The ServerSideDiff endpoint strips secret masking when IncludeMutationWebhook=true is set on an Application. The handler calls a Kubernetes SSA dry-run, gets raw Secret data back from etcd, and flies it straight into the API response. No masking. No auth check beyond "are you logged in." Base64-encoded, but that's not encryption obvipously. Versions affected: ArgoCD 3.2.0 through 3.3.8. Fixed in 3.2.11 and 3.3.9. The one saving some people: IncludeMutationWebhook isn't on by default. But if you've ever turned it on to debug mutating webhooks, you may have left a door open. If you're running ArgoCD in any serious environment, this is an upgrade you do today situation. Or at the very least, grep your Applications for that annotation and check who has read access. https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3
Post summary
The advisory discloses that ArgoCD versions 3.2.0–3.3.8 leak plaintext Kubernetes secrets when a debugging flag is enabled, and it recommends upgrading to patched releases.










