Vulnerability Details CVE-2025-59538
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.azuredevops.username and webhook.azuredevops.password are not set in the default configuration, the /api/webhook endpoint crashes the entire argocd-server process when it receives an Azure DevOps Push event whose JSON array resource.refUpdates is empty. The slice index [0] is accessed without a length check, causing an index-out-of-range panic. A single unauthenticated HTTP POST is enough to kill the process. This issue is resolved in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.2%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-59538
-
cpe:2.3:a:argoproj:argo_cd:2.10.0
-
cpe:2.3:a:argoproj:argo_cd:2.10.1
-
cpe:2.3:a:argoproj:argo_cd:2.10.10
-
cpe:2.3:a:argoproj:argo_cd:2.10.11
-
cpe:2.3:a:argoproj:argo_cd:2.10.12
-
cpe:2.3:a:argoproj:argo_cd:2.10.13
-
cpe:2.3:a:argoproj:argo_cd:2.10.14
-
cpe:2.3:a:argoproj:argo_cd:2.10.15
-
cpe:2.3:a:argoproj:argo_cd:2.10.16
-
cpe:2.3:a:argoproj:argo_cd:2.10.2
-
cpe:2.3:a:argoproj:argo_cd:2.10.3
-
cpe:2.3:a:argoproj:argo_cd:2.10.4
-
cpe:2.3:a:argoproj:argo_cd:2.10.5
-
cpe:2.3:a:argoproj:argo_cd:2.10.6
-
cpe:2.3:a:argoproj:argo_cd:2.10.7
-
cpe:2.3:a:argoproj:argo_cd:2.10.8
-
cpe:2.3:a:argoproj:argo_cd:2.10.9
-
cpe:2.3:a:argoproj:argo_cd:2.11.0
-
cpe:2.3:a:argoproj:argo_cd:2.11.1
-
cpe:2.3:a:argoproj:argo_cd:2.11.13
-
cpe:2.3:a:argoproj:argo_cd:2.11.2
-
cpe:2.3:a:argoproj:argo_cd:2.11.3
-
cpe:2.3:a:argoproj:argo_cd:2.11.4
-
cpe:2.3:a:argoproj:argo_cd:2.11.5
-
cpe:2.3:a:argoproj:argo_cd:2.11.6
-
cpe:2.3:a:argoproj:argo_cd:2.11.7
-
cpe:2.3:a:argoproj:argo_cd:2.12.0
-
cpe:2.3:a:argoproj:argo_cd:2.12.1
-
cpe:2.3:a:argoproj:argo_cd:2.12.10
-
cpe:2.3:a:argoproj:argo_cd:2.12.2
-
cpe:2.3:a:argoproj:argo_cd:2.12.3
-
cpe:2.3:a:argoproj:argo_cd:2.12.4
-
cpe:2.3:a:argoproj:argo_cd:2.12.5
-
cpe:2.3:a:argoproj:argo_cd:2.12.6
-
cpe:2.3:a:argoproj:argo_cd:2.12.7
-
cpe:2.3:a:argoproj:argo_cd:2.12.8
-
cpe:2.3:a:argoproj:argo_cd:2.12.9
-
cpe:2.3:a:argoproj:argo_cd:2.13.0
-
cpe:2.3:a:argoproj:argo_cd:2.13.1
-
cpe:2.3:a:argoproj:argo_cd:2.13.2
-
cpe:2.3:a:argoproj:argo_cd:2.13.3
-
cpe:2.3:a:argoproj:argo_cd:2.13.4
-
cpe:2.3:a:argoproj:argo_cd:2.13.8
-
cpe:2.3:a:argoproj:argo_cd:2.13.9
-
cpe:2.3:a:argoproj:argo_cd:2.14.0
-
cpe:2.3:a:argoproj:argo_cd:2.14.1
-
cpe:2.3:a:argoproj:argo_cd:2.14.10
-
cpe:2.3:a:argoproj:argo_cd:2.14.11
-
cpe:2.3:a:argoproj:argo_cd:2.14.12
-
cpe:2.3:a:argoproj:argo_cd:2.14.13
-
cpe:2.3:a:argoproj:argo_cd:2.14.14
-
cpe:2.3:a:argoproj:argo_cd:2.14.15
-
cpe:2.3:a:argoproj:argo_cd:2.14.16
-
cpe:2.3:a:argoproj:argo_cd:2.14.18
-
cpe:2.3:a:argoproj:argo_cd:2.14.19
-
cpe:2.3:a:argoproj:argo_cd:2.14.2
-
cpe:2.3:a:argoproj:argo_cd:2.14.3
-
cpe:2.3:a:argoproj:argo_cd:2.14.4
-
cpe:2.3:a:argoproj:argo_cd:2.14.5
-
cpe:2.3:a:argoproj:argo_cd:2.14.6
-
cpe:2.3:a:argoproj:argo_cd:2.14.7
-
cpe:2.3:a:argoproj:argo_cd:2.14.8
-
cpe:2.3:a:argoproj:argo_cd:2.14.9
-
cpe:2.3:a:argoproj:argo_cd:2.9.0
-
cpe:2.3:a:argoproj:argo_cd:2.9.1
-
cpe:2.3:a:argoproj:argo_cd:2.9.10
-
cpe:2.3:a:argoproj:argo_cd:2.9.11
-
cpe:2.3:a:argoproj:argo_cd:2.9.12
-
cpe:2.3:a:argoproj:argo_cd:2.9.13
-
cpe:2.3:a:argoproj:argo_cd:2.9.14
-
cpe:2.3:a:argoproj:argo_cd:2.9.15
-
cpe:2.3:a:argoproj:argo_cd:2.9.16
-
cpe:2.3:a:argoproj:argo_cd:2.9.17
-
cpe:2.3:a:argoproj:argo_cd:2.9.18
-
cpe:2.3:a:argoproj:argo_cd:2.9.19
-
cpe:2.3:a:argoproj:argo_cd:2.9.2
-
cpe:2.3:a:argoproj:argo_cd:2.9.20
-
cpe:2.3:a:argoproj:argo_cd:2.9.21
-
cpe:2.3:a:argoproj:argo_cd:2.9.3
-
cpe:2.3:a:argoproj:argo_cd:2.9.4
-
cpe:2.3:a:argoproj:argo_cd:2.9.5
-
cpe:2.3:a:argoproj:argo_cd:2.9.6
-
cpe:2.3:a:argoproj:argo_cd:2.9.7
-
cpe:2.3:a:argoproj:argo_cd:2.9.8
-
cpe:2.3:a:argoproj:argo_cd:2.9.9
-
cpe:2.3:a:argoproj:argo_cd:3.0.0
-
cpe:2.3:a:argoproj:argo_cd:3.0.1
-
cpe:2.3:a:argoproj:argo_cd:3.0.11
-
cpe:2.3:a:argoproj:argo_cd:3.0.12
-
cpe:2.3:a:argoproj:argo_cd:3.0.13
-
cpe:2.3:a:argoproj:argo_cd:3.0.14
-
cpe:2.3:a:argoproj:argo_cd:3.0.15
-
cpe:2.3:a:argoproj:argo_cd:3.0.16
-
cpe:2.3:a:argoproj:argo_cd:3.0.17
-
cpe:2.3:a:argoproj:argo_cd:3.0.18
-
cpe:2.3:a:argoproj:argo_cd:3.0.2
-
cpe:2.3:a:argoproj:argo_cd:3.0.3
-
cpe:2.3:a:argoproj:argo_cd:3.0.4
-
cpe:2.3:a:argoproj:argo_cd:3.0.5
-
cpe:2.3:a:argoproj:argo_cd:3.0.6
-
cpe:2.3:a:argoproj:argo_cd:3.0.7
-
cpe:2.3:a:argoproj:argo_cd:3.0.8
-
cpe:2.3:a:argoproj:argo_cd:3.0.9
-
cpe:2.3:a:argoproj:argo_cd:3.1.0
-
cpe:2.3:a:argoproj:argo_cd:3.1.1
-
cpe:2.3:a:argoproj:argo_cd:3.1.2
-
cpe:2.3:a:argoproj:argo_cd:3.1.3
-
cpe:2.3:a:argoproj:argo_cd:3.1.4
-
cpe:2.3:a:argoproj:argo_cd:3.1.5
-
cpe:2.3:a:argoproj:argo_cd:3.1.6
-
cpe:2.3:a:argoproj:argo_cd:3.1.7
-
cpe:2.3:a:argoproj:argo_cd:3.2.0