THREAT OPS › Threat News › [GHSA] GHSA-48p8-g2fx-3wwm (high) — Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
[GHSA] GHSA-48p8-g2fx-3wwm (high) — Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
GHSA-48p8-g2fx-3wwm Severity: high CVE: CVE-2026-54526
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
### Summary
The allow-list fix for CVE-2026-31892 (GHSA-3wf5-g532-rcrr), and its follow-up coverage of `hostNetwork`/`securityContext`/`serviceAccountName` in GHSA-3775-99mw-8rp4, is incomplete. `workflow/util/mer
Indicators of compromise
- CVE-2026-31892cve
- CVE-2026-54526cve
- kubernetes.iodomain
- argoproj.iodomain
Original source: https://github.com/advisories/GHSA-48p8-g2fx-3wwm