<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:11:43 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337269</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337269</link>
      <description>EUVD-2026-337269</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337269</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40886</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40886</link>
      <description>&lt;p&gt;Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer&amp;#39;s podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pod-gc-strategy annotation. Because the panic occurs inside an informer goroutine (outside the controller&amp;#39;s recover() scope), it crashes the entire controller process. The poisoned pod persists across restarts, causing a crash loop that halts all workflow processing until the pod is manually deleted. This vulnerability is fixed in 4.0.5 and 3.7.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer&amp;#39;s podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pod-gc-strategy annotation. Because the panic occurs inside an informer goroutine (outside the controller&amp;#39;s recover() scope), it crashes the entire controller process. The poisoned pod persists across restarts, causing a crash loop that halts all workflow processing until the pod is manually deleted. This vulnerability is fixed in 4.0.5 and 3.7.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40886</guid>
    </item>
    <item>
      <title>GHSA-5jv8-h7qh-rf5p — Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5jv8-h7qh-rf5p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-workflows/v4, Go: github.com/argoproj/argo-workflows/v3&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An unchecked array index in the pod informer&amp;#39;s `podGCFromPod()` function causes a controller-wide panic when a workflow pod carries a malformed `workflows.argoproj.io/pod-gc-strategy` annotation. Because the panic occurs inside an informer goroutine (outside the controller&amp;#39;s `recover()` scope), it crashes the entire controller process. The poisoned pod persists across restarts, causing a crash loop that halts all workflow processing until the pod is manually deleted.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`podGCFromPod()` splits the annotation value on &amp;#34;/&amp;#34; and unconditionally accesses `parts[1]`:&lt;/p&gt;
&lt;p&gt;```go
func podGCFromPod(pod *apiv1.Pod) wfv1.PodGC {
    if val, ok := pod.Annotations[common.AnnotationKeyPodGCStrategy]; ok {
        parts := strings.Split(val, &amp;#34;/&amp;#34;)
        return wfv1.PodGC{Strategy: wfv1.PodGCStrategy(parts[0]), DeleteDelayDuration: parts[1]}
    }
    return wfv1.PodGC{Strategy: wfv1.PodGCOnPodNone}
}
```&lt;/p&gt;
&lt;p&gt;If the annotation value contains no &amp;#34;/&amp;#34;, `parts` has length 1 and `parts[1]` panics with index out of range.&lt;/p&gt;
&lt;p&gt;The code was introduced in [#14129](https://github.com/argoproj/argo-workflows/issues/14129) and  affects versions:&lt;/p&gt;
&lt;p&gt;- 3.6.x: v3.6.5 through v3.6.19 (backport in [#14263](https://github.com/argoproj/argo-workflows/issues/14263))
  - 3.7.x: v3.7.0-rc1 through v3.7.12
  - 4.x: v4.0.0-rc1 through v4.0.3
  - Not affected: v3.6.4 and earlier&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Apply this workflow to a cluster running the Argo Workflows controller:&lt;/p&gt;
&lt;p&gt;```bash
kubectl apply -n argo -f - &amp;lt;&amp;lt;&amp;#39;EO…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-workflows/v4, Go: github.com/argoproj/argo-workflows/v3&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An unchecked array index in the pod informer&amp;#39;s `podGCFromPod()` function causes a controller-wide panic when a workflow pod carries a malformed `workflows.argoproj.io/pod-gc-strategy` annotation. Because the panic occurs inside an informer goroutine (outside the controller&amp;#39;s `recover()` scope), it crashes the entire controller process. The poisoned pod persists across restarts, causing a crash loop that halts all workflow processing until the pod is manually deleted.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`podGCFromPod()` splits the annotation value on &amp;#34;/&amp;#34; and unconditionally accesses `parts[1]`:&lt;/p&gt;
&lt;p&gt;```go
func podGCFromPod(pod *apiv1.Pod) wfv1.PodGC {
    if val, ok := pod.Annotations[common.AnnotationKeyPodGCStrategy]; ok {
        parts := strings.Split(val, &amp;#34;/&amp;#34;)
        return wfv1.PodGC{Strategy: wfv1.PodGCStrategy(parts[0]), DeleteDelayDuration: parts[1]}
    }
    return wfv1.PodGC{Strategy: wfv1.PodGCOnPodNone}
}
```&lt;/p&gt;
&lt;p&gt;If the annotation value contains no &amp;#34;/&amp;#34;, `parts` has length 1 and `parts[1]` panics with index out of range.&lt;/p&gt;
&lt;p&gt;The code was introduced in [#14129](https://github.com/argoproj/argo-workflows/issues/14129) and  affects versions:&lt;/p&gt;
&lt;p&gt;- 3.6.x: v3.6.5 through v3.6.19 (backport in [#14263](https://github.com/argoproj/argo-workflows/issues/14263))
  - 3.7.x: v3.7.0-rc1 through v3.7.12
  - 4.x: v4.0.0-rc1 through v4.0.3
  - Not affected: v3.6.4 and earlier&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Apply this workflow to a cluster running the Argo Workflows controller:&lt;/p&gt;
&lt;p&gt;```bash
kubectl apply -n argo -f - &amp;lt;&amp;lt;&amp;#39;EO…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5jv8-h7qh-rf5p</guid>
    </item>
  </channel>
</rss>
