Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

GHSA-mf7q-r4rv-jv94

Crossplane-runtime versions 2.3.0 through 2.3.2 contain a time-of-check time-of-use vulnerability in package signature verification. The flaw exists because the package manager resolves tag references independently during signature verification and image fetching operations, rather than using a single resolved digest for both steps. When a user configures image signature verification through the ImageConfig mechanism and installs a package using a tag reference from an untrusted OCI registry, a malicious registry operator can serve a correctly signed image during the verification phase and subsequently serve a different unsigned image during the installation phase. This occurs because the tag-to-digest resolution is performed twice, allowing the registry to return different manifests for each request. The impact is a compromise of integrity guarantees, permitting the installation of unverified or malicious package content despite signature verification being enabled. The affected funct...
Back to all
CVE

GHSA-mf7q-r4rv-jv94

Crossplane-runtime versions 2.3.0 through 2.3.2 contain a time-of-check time-of-use vulnerability in package signature verification. The flaw exists because the package manager resolves tag references independently during signature verification and image fetching operations, rather than using a single resolved digest for both steps. When a user configures image signature verification through the ImageConfig mechanism and installs a package using a tag reference from an untrusted OCI registry, a malicious registry operator can serve a correctly signed image during the verification phase and subsequently serve a different unsigned image during the installation phase. This occurs because the tag-to-digest resolution is performed twice, allowing the registry to return different manifests for each request. The impact is a compromise of integrity guarantees, permitting the installation of unverified or malicious package content despite signature verification being enabled. The affected funct...

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
-
C
H
U
9
-
3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Related Resources

No items found.

References

Severity

9

CVSS Score
0
10

Basic Information

Base CVSS
9
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
v2.4.0-rc.0,v2.3.0-rc.1,v2.0.0-20260413214920-ae60667ea62b
Fix Available
v2.3.3,v2.0.0-20260616192746-bee99c6cd6ca

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading