{"id":"CVE-2025-55191","aliases":["BIT-argo-cd-2025-55191","GHSA-g88p-r42r-ppp9","GO-2025-3994"],"url":"https://o3.security/vulnerability/CVE-2025-55191","summary":"Repository Credentials Race Condition Crashes Argo CD Server","details":"### Summary\n\nA race condition in the repository credentials handler can cause the Argo CD server to panic and crash when concurrent operations are performed on the same repository URL.\n\n### Details\nThe vulnerability is located in numerous repository related handlers in the `util/db/repository_secrets.go` file. For example, in the `secretToRepoCred` function. The issue manifests as a concurrent map access panic:\n\n```\nconcurrent map read and map write\n...\ngoroutine 1104 [running]:\ngithub.com/argoproj/argo-cd/v2/util/db.(*secretsRepositoryBackend).secretToRepoCred(0xc000e50ea8?, 0xc000c65540)\n        /go/src/github.com/argoproj/argo-cd/util/db/repository_secrets.go:404 +0x31e\n```\n\nThe race condition occurs due to:\n1. Concurrent repository credential operations (create/update/delete) accessing the same map\n2. Kubernetes informer re-syncs happening simultaneously\n3. Background watchers updating the same secret data\n4. No mutex protection for map access\n\nA valid API token with `repositories` resource permissions (`create`, `update`, or `delete` actions) is required to trigger the race condition.\n\n### Impact\n\nThis vulnerability causes the entire Argo CD server to crash and become unavailable. Attackers can repeatedly and continuously trigger the race condition to maintain a denial-of-service state, disrupting all GitOps operations. Default ArgoCD configuration is vulnerable.\n\nThe affected code was originally introduced in [PR #6103](https://github.com/argoproj/argo-cd/pull/6103) and released in [v2.1.0](https://github.com/argoproj/argo-cd/releases/tag/v2.1.0).\n\nThis data race was addressed by deep-copying the `Secret` objects before reading/writing.\n\n### Credits\n\nThis vulnerability was found, reported and fixed by:\n\n@thevilledev\n\nThe Argo team would like to thank him for his responsible disclosure and constructive communications during the resolve of this issue.","published":"2025-09-30T22:52:19.838Z","modified":"2026-08-24T10:25:33.348750151Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00472,"percentile":0.39835,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/argoproj/argo-cd/v2","fixedVersion":"2.14.20"},{"ecosystem":"Go","name":"github.com/argoproj/argo-cd/v3","fixedVersion":"3.2.0-rc2"},{"ecosystem":"Go","name":"github.com/argoproj/argo-cd/v3","fixedVersion":"3.1.8"},{"ecosystem":"Go","name":"github.com/argoproj/argo-cd/v3","fixedVersion":"3.0.19"}],"fix":{"url":"https://github.com/argoproj/argo-cd/commit/701bc50d01c752cad96185f848088d287a97c7b7","label":"argoproj/argo-cd@701bc50"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55191.json"},{"type":"ADVISORY","url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-g88p-r42r-ppp9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55191"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/701bc50d01c752cad96185f848088d287a97c7b7"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/pull/6103"},{"type":"PACKAGE","url":"https://github.com/argoproj/argo-cd"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2025-3994"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T10:25:33.348750151Z"}}