THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mf7q-r4rv-jv94 (high) — Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

[GHSA] GHSA-mf7q-r4rv-jv94 (high) — Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

medgithub_advisoriesPublished 2026-08-27

GHSA-mf7q-r4rv-jv94 Severity: high CVE: None

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

## Summary

Crossplane allows package signature verification to be configured via the `ImageConfig` mechanism. When enabled, the package manager uses cosign to verify that packages are correctly signed before

Original source: https://github.com/advisories/GHSA-mf7q-r4rv-jv94