Github.com/crossplane/crossplane
This hub aggregates every CVE we track for Github.com/crossplane/crossplane, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
LOW1HIGH1MEDIUM1
Monthly trend
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
2024-102026-09
Latest CVEs
The 5 most recently published vulnerabilities affecting Github.com/crossplane/crossplane.
- GHSA-wfqx-gjrf-g28rCrossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
- GHSA-7h65-4p22-39j6github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
- CVE-2023-38495Crossplane vulnerable to possible image tampering from missing image validation for Packages8.3
- CVE-2023-37900Crossplane vulnerable to denial of service from large image3.4
- CVE-2023-27484Unchecked fieldpath index in Composition's patches can lead to arbitrary memory allocation in crossplane6.2
Product normalization is registry-driven with AI assist and human review. How it works