RATATOSKRATATOSK
Sign in

Argo

v3.3.13CI/CD & App Delivery
Jul 31, 2026

Argo CD v3.3.13 is a patch release fixing a form-data security update (CVE-2026-12143) and nine operational bugs across health checks, credential handling, source depth resolution, reconciliation timing, and UI display.

  • securityForm-data CVE-2026-12143 fixed in UI

    The form-data library in the UI has been updated to 4.0.6 to fix CVE-2026-12143. This patch applies to all Argo CD 3.3 deployments running the UI component.

Key changes (10)

  • Security: form-data updated to 4.0.6 for CVE-2026-12143 in UI
  • Helm registry passwords no longer exposed; now passed through stdin
  • Repo-server now respects referenced source depth instead of primary source depth
  • Auth reconciliation separated from server-side apply to avoid conflicts
  • Revision-path update behavior restored via UpdateRevisionForPaths
  • UI no longer shows deleted resources as present
  • Replace sync operations no longer clobber excluded fields
  • Dex config environment variable substitution restored
  • argocd-cmd-params-cm mounted in repo-server to enable pprof
  • golang.org/x/crypto bumped to 0.53.0
Add Argo to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack