Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31767 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CD's /api/webhook endpoint crashes when receiving a malformed Bitbucket Server payload (non-array repository.links.clone field). A single unauthenticated request triggers CrashLoopBackOff, and targeting all replicas causes complete API outage. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19. |
Github GHSA |
GHSA-f9gq-prrc-hrhc | Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload |
Tue, 07 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj argo Cd
|
|
| CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* cpe:2.3:a:argoproj:argo_cd:3.2.0:rc1:*:*:*:*:*:* |
|
| Vendors & Products |
Argoproj argo Cd
|
Mon, 06 Oct 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-248 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj
Argoproj argo-cd |
|
| Vendors & Products |
Argoproj
Argoproj argo-cd |
Wed, 01 Oct 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CD's /api/webhook endpoint crashes when receiving a malformed Bitbucket Server payload (non-array repository.links.clone field). A single unauthenticated request triggers CrashLoopBackOff, and targeting all replicas causes complete API outage. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19. | |
| Title | Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload | |
| Weaknesses | CWE-703 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-02T15:54:24.950Z
Reserved: 2025-09-17T17:04:20.373Z
Link: CVE-2025-59531
Updated: 2025-10-02T15:35:42.677Z
Status : Analyzed
Published: 2025-10-01T21:16:43.377
Modified: 2025-10-07T14:39:29.373
Link: CVE-2025-59531
OpenCVE Enrichment
Updated: 2025-10-02T08:38:19Z
EUVD
Github GHSA