Resource exhaustion in Argo Workflows - #VU126911
Published: April 23, 2026
Argo Workflows
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory consumption in the webhook interceptor when handling requests to the /api/v1/events/ endpoint with an extremely large body before authentication or signature verification. A remote attacker can send a specially crafted request with an extremely large body to cause a denial of service.
The issue can cause the Argo Server to allocate excessive memory and potentially crash with an out-of-memory condition.