Vulnerability GO-2026-5709
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
June 25, 2026 at 10:34 PM UTC
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag in github.com/crossplane/crossplane
v0.1.0 - v1.21.0-rc.0
v0.1.0 - v1.21.0-rc.0
Summary
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag in github.com/crossplane/crossplane
Details
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag in github.com/crossplane/crossplane
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
3 months ago
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
v2.0.0-preview.0 - v2.2.2 and v2.3.0-rc.0 - v2.3.2 GHSA-wfqx-gjrf-g28r
v2.0.0-preview.0 - v2.2.2 and v2.3.0-rc.0 - v2.3.2 GHSA-wfqx-gjrf-g28r
Critical
3 months ago
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
v2.0.0-preview.0 - v2.2.2 and v2.3.0-rc.0 - v2.3.2 GHSA-wfqx-gjrf-g28r
v2.0.0-preview.0 - v2.2.2 and v2.3.0-rc.0 - v2.3.2 GHSA-wfqx-gjrf-g28r
Unknown
1 year ago
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
v1.15.5 GO-2024-3219
v1.15.5 GO-2024-3219
Critical
1 year ago
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
v1.15.5 and v1.16.2 and v1.17.1 GHSA-7h65-4p22-39j6
v1.15.5 and v1.16.2 and v1.17.1 GHSA-7h65-4p22-39j6
Unknown
2 years ago
Denial of service from large image in github.com/crossplane/crossplane
v0.1.0 - v1.11.4 GO-2023-1979
v0.1.0 - v1.11.4 GO-2023-1979
Impacted packages
Timeline
Published
3 months ago
June 25, 2026 at 10:34 PM UTC
Last Modified
3 months ago
June 25, 2026 at 11:01 PM UTC