github.com/crossplane/crossplane vulnerabilities
CVEs whose affected-version data names the github.com/crossplane/crossplane package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
GHSA-wfqx-gjrf-g28rCritical· 9.0Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
▾ Midnightcrossplane · github.com/crossplane/crossplane/v2via GHSA
GO-2024-3219Nonegithub.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
▾ Sunlitcrossplane · github.com/crossplane/crossplanevia OSV
GHSA-7h65-4p22-39j6Critical· 9.8github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
▾ Midnightcrossplane · github.com/crossplane/crossplanevia OSV
CVE-2023-37900Low· 3.4Denial of service from large image
Denial of service from large image
▾ Sunlitcrossplane · github.com/crossplane/crossplaneEPSS 0.62%via OSV