GO-2026-6302
Dashboard / Vulnerabilities / GO-2026-6302
Summary: Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
Details: Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
References: https://github.com/crossplane/crossplane-runtime/security/advisories/GHSA-mf7q-r4rv-jv94, https://github.com/crossplane/crossplane-runtime/pull/1038, https://github.com/crossplane/crossplane-runtime/commit/bee99c6cd6ca81878acca2940a2f0a02169fc208, https://github.com/crossplane/crossplane-runtime/releases/tag/v2.3.3
Affected packages
Package
Name: github.com/crossplane/crossplane-runtime/v2
Purl: pkg:golang/github.com/crossplane/crossplane-runtime/v2
Affected ranges
Type: SEMVER
Events:
