Skip to main content

Argo CD Security-Hardened Images

Security Scan 2025-06-16

Argo CD security-hardened images include precisely what is needed to run Argo CD. As a result, we build smaller-sized images with a reduced number of CVEs. By not including a package manager and inserting the needed runtime dependencies, the attack surface is significantly reduced.

Below you will find the weekly-updated security scans of Akuity's security-hardened Argo CD images compared with the open source images.


Akuity v2.14.14-distroless vs Argo CD v2.14.14

Full list of open source Argo CD vulnerabilities in this release

quay.io/akuity/argocd:v2.14.14-distroless

Vulnerabilities (1)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
git-lfsCVE-2025-22874HIGH3.6.1-r73.6.1-r8

usr/local/bin/argocd

Vulnerabilities (0)

usr/local/bin/gpg-wrapper.sh

Vulnerabilities (2)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
stdlibCVE-2024-34156HIGHv1.21.131.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.21.131.23.10, 1.24.4

usr/local/bin/helm

Vulnerabilities (3)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
golang.org/x/cryptoCVE-2024-45337CRITICALv0.27.00.31.0
golang.org/x/cryptoCVE-2025-22869HIGHv0.27.00.35.0
stdlibCVE-2025-22874HIGHv1.22.71.23.10, 1.24.4

usr/local/bin/kustomize

Vulnerabilities (2)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
stdlibCVE-2024-34156HIGHv1.21.121.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.21.121.23.10, 1.24.4

Akuity v2.13.8-distroless vs Argo CD v2.13.8

Full list of open source Argo CD vulnerabilities in this release

quay.io/akuity/argocd:v2.13.8-distroless

Vulnerabilities (1)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
git-lfsCVE-2025-22874HIGH3.6.1-r73.6.1-r8

usr/local/bin/argocd

Vulnerabilities (3)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
github.com/golang-jwt/jwtCVE-2025-30204HIGHv3.2.2+incompatible
golang.org/x/cryptoCVE-2025-22869HIGHv0.32.00.35.0
stdlibCVE-2025-22874HIGHv1.23.11.23.10, 1.24.4

usr/local/bin/gpg-wrapper.sh

Vulnerabilities (2)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
stdlibCVE-2024-34156HIGHv1.21.131.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.21.131.23.10, 1.24.4

usr/local/bin/helm

Vulnerabilities (4)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
golang.org/x/cryptoCVE-2024-45337CRITICALv0.25.00.31.0
golang.org/x/cryptoCVE-2025-22869HIGHv0.25.00.35.0
stdlibCVE-2024-34156HIGHv1.22.61.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.22.61.23.10, 1.24.4

usr/local/bin/kustomize

Vulnerabilities (2)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
stdlibCVE-2024-34156HIGHv1.21.121.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.21.121.23.10, 1.24.4

Akuity v2.12.12-distroless vs Argo CD v2.12.12

Full list of open source Argo CD vulnerabilities in this release

quay.io/akuity/argocd:v2.12.12-distroless

Vulnerabilities (1)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
git-lfsCVE-2025-22874HIGH3.6.1-r53.6.1-r8

usr/local/bin/argocd

Vulnerabilities (7)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
github.com/argoproj/argo-cd/v2CVE-2025-47933CRITICAL2.12.112.13.8, 2.14.13
github.com/golang-jwt/jwtCVE-2025-30204HIGHv3.2.2+incompatible
golang.org/x/cryptoCVE-2025-22869HIGHv0.31.00.35.0
k8s.io/kubernetesCVE-2024-10220HIGHv1.29.61.28.12, 1.29.7, 1.30.3
k8s.io/kubernetesCVE-2024-5321HIGHv1.29.61.27.16, 1.28.12, 1.29.7, 1.30.3
stdlibCVE-2024-34156HIGHv1.22.41.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.22.41.23.10, 1.24.4

usr/local/bin/gpg-wrapper.sh

Vulnerabilities (2)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
stdlibCVE-2024-34156HIGHv1.21.131.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.21.131.23.10, 1.24.4

usr/local/bin/helm

Vulnerabilities (5)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
github.com/docker/dockerCVE-2024-41110CRITICALv25.0.5+incompatible23.0.15, 26.1.5, 27.1.1, 25.0.6
golang.org/x/cryptoCVE-2024-45337CRITICALv0.21.00.31.0
golang.org/x/cryptoCVE-2025-22869HIGHv0.21.00.35.0
stdlibCVE-2024-34156HIGHv1.22.41.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.22.41.23.10, 1.24.4

usr/local/bin/kustomize

Vulnerabilities (3)
The below table displays CRITICAL and HIGH severence vulnerabilities only
PackageIDSeverityInstalled VersionFixed Version
stdlibCVE-2024-24790CRITICALv1.21.101.21.11, 1.22.4
stdlibCVE-2024-34156HIGHv1.21.101.22.7, 1.23.1
stdlibCVE-2025-22874HIGHv1.21.101.23.10, 1.24.4