Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CD's /api/webhook endpoint crashes when receiving a malformed Bitbucket Server payload (non-array repository.links.clone field). A single unauthenticated request triggers CrashLoopBackOff, and targeting all replicas causes complete API outage. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 07 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Argoproj argo Cd | |
| CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* cpe:2.3:a:argoproj:argo_cd:3.2.0:rc1:*:*:*:*:*:* | |
| Vendors & Products | Argoproj argo Cd | 
Mon, 06 Oct 2025 22:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-248 | |
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Argoproj Argoproj argo-cd | |
| Vendors & Products | Argoproj Argoproj argo-cd | 
Wed, 01 Oct 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CD's /api/webhook endpoint crashes when receiving a malformed Bitbucket Server payload (non-array repository.links.clone field). A single unauthenticated request triggers CrashLoopBackOff, and targeting all replicas causes complete API outage. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19. | |
| Title | Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload | |
| Weaknesses | CWE-703 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-01T20:49:35.428Z
Updated: 2025-10-02T15:54:24.950Z
Reserved: 2025-09-17T17:04:20.373Z
Link: CVE-2025-59531
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-02T15:35:42.677Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-10-01T21:16:43.377
Modified: 2025-10-07T14:39:29.373
Link: CVE-2025-59531
 Redhat
                        Redhat