{"id":"CGA-c69w-79wp-cp9f","modified":"2026-07-17T18:50:52.626284801Z","published":"2025-10-30T19:11:30Z","upstream":["CVE-2025-62156","GHSA-p84v-gxvw-73pf","GO-2025-4023"],"references":[{"type":"WEB","url":"https://github.com/argoproj/argo-workflows/blob/946a2d6b9ac3309371fe47f49ae94c33ca7d488d/workflow/executor/executor.go#L993"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62156.json"},{"type":"ADVISORY","url":"https://github.com/argoproj/argo-workflows/security/advisories/GHSA-p84v-gxvw-73pf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62156"},{"type":"FIX","url":"https://github.com/argoproj/argo-workflows/commit/5659ad9b641fcf52c04ed594cd6493f9170f6011"},{"type":"FIX","url":"https://github.com/argoproj/argo-workflows/commit/9f6bc5d236cd1b24d607943384511d71ad17a4c3"}],"affected":[{"package":{"name":"argo-workflow-cli-fips-3.6","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/argo-workflow-cli-fips-3.6?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.12-r0"}]}],"ecosystem_specific":{"components":[{"latest_event_timestamp":"2025-10-15T20:40:39Z","architecture":"aarch64","component_name":"github.com/argoproj/argo-workflows/v3","component_version":"v3.6.11+dirty","component_type":"go-module","component_location":"/usr/bin/workflow-controller","component_purl":"pkg:golang/github.com/argoproj/argo-workflows/v3@v3.6.11%2Bdirty","latest_event_status":"fixed"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-c69w-79wp-cp9f.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}