Vulnerabilities

Last updated 58 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
github.com/crossplane/crossplane Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag Critical 9.0 3 months ago 5 hours ago
github.com/crossplane/crossplane/v2 Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag Critical 9.0 3 months ago 5 hours ago
github.com/crossplane/crossplane-runtime/v2 Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check High Risk 8.0 1 month ago 19 days ago
github.com/crossplane/crossplane Possible image tampering from missing image validation for Packages High Risk 8.3 3 years ago 19 days ago
github.com/crossplane/crossplane Crossplane-runtime contains Improper Input Validation via Compositions Medium Risk 6.2 3 years ago 19 days ago
github.com/crossplane/crossplane-runtime fieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtime Medium Risk 5.9 3 years ago 19 days ago
github.com/crossplane/crossplane Denial of service from large image Low Risk 3.4 3 years ago 19 days ago
github.com/crossplane/crossplane-runtime/v2 Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2 Unknown 20 days ago 20 days ago
github.com/crossplane/crossplane github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses Critical 9.8 1 year ago 1 month ago
github.com/crossplane/crossplane github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses Unknown 1 year ago 1 month ago
github.com/crossplane/crossplane Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag in github.com/crossplane/crossplane Unknown 3 months ago 3 months ago
github.com/crossplane/crossplane/v2 Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag in github.com/crossplane/crossplane Unknown 3 months ago 3 months ago
github.com/crossplane/crossplane Denial of service from large image in github.com/crossplane/crossplane Unknown 2 years ago 7 months ago
github.com/crossplane/crossplane Possible image tampering from missing image validation for Packages in github.com/crossplane/crossplane Unknown 2 years ago 7 months ago
github.com/crossplane/crossplane-runtime Out-of-memory panic in github.com/crossplane/crossplane-runtime Unknown 3 years ago 2 years ago