In Argo CD versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9 a critical severity vulnerability CVE-2026-42880 was detected. This vulnerability allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server’s Server-Side Apply dry-run mechanism due to a missing authorization and data-masking gap in Argo CD’s ServerSideDiff endpoint. To address this issue, users should upgrade Argo CD to versions 3.2.11 or 3.3.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42880.
Read more Developer ToolsIn Prefect versions up to 3.6.21 a high severity vulnerability CVE-2026-7722 was detected. This vulnerability allows remote attackers to bypass authentication by manipulating the endswith function within the /api/health endpoint. To address this issue, users should upgrade Prefect to version 3.6.22. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-7722.
Read more Developer ToolsIn Argo CD versions 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9 a high severity vulnerability CVE-2026-43824 was detected. This vulnerability allows attackers to read cleartext Kubernetes Secret data via the ServerSideDiff feature. To address this issue, users should upgrade Argo CD to versions 3.2.11 or 3.3.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-43824.
Read more Developer ToolsIn Prefect versions up to 3.6.13 a high severity vulnerability CVE-2026-7723 was detected. This vulnerability allows remote attackers to bypass authentication via the /api/events/in WebSocket endpoint. To address this issue, users should upgrade Prefect to version 3.6.14. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-7723.
Read more Developer ToolsIn Jenkins GitHub Branch Source Plugin version 1967.vdea_d580c1a_b_a_ and earlier a medium severity vulnerability CVE-2026-42522 was detected. This vulnerability allows attackers with Overall/Read permission to initiate connections to attacker-specified URLs using attacker-controlled GitHub App credentials due to a missing permission check. To address this issue, users should upgrade Jenkins GitHub Branch Source plugin to version 1967.1969.v205fd594c821. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42522.
Read more Developer ToolsIn Jenkins GitHub Plugin version 1.46.0 and earlier a high severity vulnerability CVE-2026-42523 was detected. This vulnerability allows non-anonymous attackers with Overall/Read permission to execute stored cross-site scripting (XSS) due to improper handling of the current job URL in JavaScript used by the “GitHub hook trigger for GITScm polling” feature. To address this issue, users should upgrade Jenkins GitHub plugin to version 1.46.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42523.
Read more Developer ToolsIn OpenShift Container Platform all versions a medium severity vulnerability CVE-2026-7309 was detected. This vulnerability allows attackers with the ‘edit’ ClusterRole to inject arbitrary environment variables, such as LD_PRELOAD or http_proxy, into docker-build containers through the buildconfigs/instantiate API, leading to information disclosure that impacts the confidentiality of build traffic. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-7309.
Read more Developer ToolsIn GitLab CE/EE versions from 18.11 before 18.11.1 low severity vulnerability CVE-2026-3254 was detected. This vulnerability allows attackers to load unauthorized content into another user’s browser due to improper input validation in the Mermaid sandbox. To address this issue users must upgrade to 18.11.1 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-3254.
Read more Developer ToolsIn GitLab CE/EE versions 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 medium severity vulnerability CVE-2026-1660 was detected. This vulnerability allows attackers to cause a denial of service when importing issues due to improper input validation and the allocation of resources without limits or throttling. To address this issue users must upgrade to 18.9.6, 18.10.4, or 18.11.1 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1660.
Read more Developer Tools