Improper Check or Handling of Exceptional Conditions in Argo CD - CVE-2025-59531
Published: May 2, 2026
Argo CD
Argo
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper check or handling of exceptional conditions in the argocd-server webhook handler when processing a Bitbucket-Server webhook payload. A remote attacker can send a specially crafted webhook request to cause a denial of service.
With the default configuration, exploitation is possible when no webhook.bitbucketserver.secret is set, and a malformed repository.links.clone field can panic the argocd-server process.