A race condition vulnerability in the SessionManager of CNCF: Cloud Native Computing Foundation Argo CD v3.0.6 allows attackers to bypass rate limiting and perform a brute force attack via repeated crafted requests.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj
Argoproj argo-cd |
|
| Vendors & Products |
Argoproj
Argoproj argo-cd |
Fri, 09 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Race Condition in Argo CD Session Manager Enables Brute‑Force Attack | |
| Weaknesses | CWE-362 CWE-400 |
Fri, 09 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A race condition vulnerability in the SessionManager of CNCF: Cloud Native Computing Foundation Argo CD v3.0.6 allows attackers to bypass rate limiting and perform a brute force attack via repeated crafted requests. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-09T16:05:43.861Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61560
No data.
Status : Awaiting Analysis
Published: 2026-10-09T17:16:41.183
Modified: 2026-10-09T17:41:15.270
Link: CVE-2025-61560
No data.
OpenCVE Enrichment
Updated: 2026-10-09T18:30:11Z