Argo
v3.3.13CI/CD & App DeliveryJul 31, 2026
Argo CD v3.3.13 is a patch release fixing a form-data security update (CVE-2026-12143) and nine operational bugs across health checks, credential handling, source depth resolution, reconciliation timing, and UI display.
securityForm-data CVE-2026-12143 fixed in UI
The form-data library in the UI has been updated to 4.0.6 to fix CVE-2026-12143. This patch applies to all Argo CD 3.3 deployments running the UI component.
Key changes (10)
- Security: form-data updated to 4.0.6 for CVE-2026-12143 in UI
- Helm registry passwords no longer exposed; now passed through stdin
- Repo-server now respects referenced source depth instead of primary source depth
- Auth reconciliation separated from server-side apply to avoid conflicts
- Revision-path update behavior restored via UpdateRevisionForPaths
- UI no longer shows deleted resources as present
- Replace sync operations no longer clobber excluded fields
- Dex config environment variable substitution restored
- argocd-cmd-params-cm mounted in repo-server to enable pprof
- golang.org/x/crypto bumped to 0.53.0
Add Argo to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.