THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-48p8-g2fx-3wwm (high) — Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

[GHSA] GHSA-48p8-g2fx-3wwm (high) — Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

highgithub_advisoriesPublished 2026-08-13

GHSA-48p8-g2fx-3wwm Severity: high CVE: CVE-2026-54526

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

### Summary

The allow-list fix for CVE-2026-31892 (GHSA-3wf5-g532-rcrr), and its follow-up coverage of `hostNetwork`/`securityContext`/`serviceAccountName` in GHSA-3775-99mw-8rp4, is incomplete. `workflow/util/mer

Indicators of compromise

Original source: https://github.com/advisories/GHSA-48p8-g2fx-3wwm