{"id":"GO-2026-6302","aliases":["GHSA-mf7q-r4rv-jv94"],"title":"Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2","summary":"Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2","severity":"none","vendor":"crossplane","product":"github.com/crossplane/crossplane-runtime/v2","ecosystem":"go","affected":["github.com/crossplane/crossplane-runtime/v2 >= 2.4.0-rc.0, < 2.4.0-rc.1"],"patched":["github.com/crossplane/crossplane-runtime/v2 2.4.0-rc.1"],"published":"2026-09-09","updated":"2026-09-09","sourceUpdated":"2026-09-09T18:15:12.313380904Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GO-2026-6302","references":[{"url":"https://github.com/crossplane/crossplane-runtime/security/advisories/GHSA-mf7q-r4rv-jv94"},{"url":"https://github.com/crossplane/crossplane-runtime/pull/1038"},{"url":"https://github.com/crossplane/crossplane-runtime/commit/bee99c6cd6ca81878acca2940a2f0a02169fc208"},{"url":"https://github.com/crossplane/crossplane-runtime/releases/tag/v2.3.3"}],"tags":["osv","go"],"ingestedAt":"2026-09-10T03:08:29.637Z","slug":"GO-2026-6302","body":"## Overview\n\nSignature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2\n\n## Affected packages\n\n- `github.com/crossplane/crossplane-runtime/v2 >= 2.4.0-rc.0, < 2.4.0-rc.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/crossplane/crossplane-runtime/v2 2.4.0-rc.1`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}